Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly Sitekit sitekit allows Stored XSS.This issue affects Sitekit: from n/a through <= 1.9.
Published: 2025-06-20
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Sitekit, a WordPress plugin by webvitaly, contains a stored cross‑site scripting flaw that allows an attacker to inject malicious JavaScript into the plugin’s output. When the compromised input is loaded by a user’s browser, the script executes with the user’s privileges, enabling session hijacking, defacement, or data exfiltration. The vulnerability is classified as CWE‑79 and can undermine the confidentiality, integrity, and availability of the affected WordPress site.

Affected Systems

All installations of Sitekit, version 1.9 and earlier, are affected. The plugin is used on WordPress sites, and any instance running a vulnerable version is at risk. Administrators should verify the plugin version and ensure it is greater than 1.9.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score of <1% suggests that real‑world exploitation is expected to be uncommon at this time. The vulnerability is not listed in CISA’s KEV catalog, and there is no known public exploit. Based on the description, it is inferred that an attacker would need to inject malicious input through the Sitekit settings or other input fields, which the plugin then serves unescaped to other users. Once executed, the code runs in the context of the target visitor’s browser, effectively bypassing the plugin’s intended restrictions.

Generated by OpenCVE AI on May 1, 2026 at 07:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Sitekit to the latest available version that addresses the stored XSS flaw.
  • If an immediate update is not feasible, disable or remove the Sitekit plugin to eliminate the XSS vector.
  • Review any content stored by the plugin for injected scripts, and manually sanitize or delete items that contain malicious code.

Generated by OpenCVE AI on May 1, 2026 at 07:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19018 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly Sitekit allows Stored XSS. This issue affects Sitekit: from n/a through 1.9.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly Sitekit allows Stored XSS. This issue affects Sitekit: from n/a through 1.9. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly Sitekit sitekit allows Stored XSS.This issue affects Sitekit: from n/a through <= 1.9.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 24 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly Sitekit allows Stored XSS. This issue affects Sitekit: from n/a through 1.9.
Title WordPress Sitekit plugin <= 1.9 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:17.026Z

Reserved: 2025-06-11T16:08:50.967Z

Link: CVE-2025-50047

cve-icon Vulnrichment

Updated: 2025-06-24T13:38:24.780Z

cve-icon NVD

Status : Deferred

Published: 2025-06-20T15:15:31.150

Modified: 2026-04-23T15:32:02.650

Link: CVE-2025-50047

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T07:30:11Z

Weaknesses