Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daman Jeet Finale Lite finale-woocommerce-sales-countdown-timer-discount allows Reflected XSS.This issue affects Finale Lite: from n/a through <= 2.20.0.
Published: 2025-10-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an instance of Improper Neutralization of Input During Web Page Generation, which allows an attacker to inject and execute arbitrary JavaScript in the context of the victim’s browser. The issue manifests as reflected XSS, meaning the malicious code is embedded in a request that is returned unfiltered by the plugin and displayed to the user. This can lead to cookie theft, session hijacking, site defacement, or redirection to malicious sites.

Affected Systems

The affected software is the Finale Lite plugin created by Daman Jeet, used in WordPress installations. All versions up to and including 2.20.0 are affected; no later releases have been listed as vulnerable in the advisory.

Risk and Exploitability

The CVSS score of 7.1 classifies this vulnerability as High, indicating significant impact if exploited. With an EPSS score of less than 1%, the likelihood of real‑world exploitation is currently low, but the presence of reflected XSS means it can be triggered via crafted URLs or form inputs that are reflected back to the user. The vulnerability is not listed in the CISA KEV catalog, so no known public exploits are currently documented. If an attacker successfully exploits the flaw, they can run arbitrary client‑side code in the victim’s browser, potentially leading to credential compromise or further phishing attacks.

Generated by OpenCVE AI on April 29, 2026 at 16:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Finale Lite to the latest patch version (check the plugin author’s site for updates).
  • If an upgrade is not immediately possible, harden the site with a Web Application Firewall that blocks or sanitizes reflected XSS payloads in URL parameters.
  • Disable any feature of the plugin that handles user‑supplied input until a patched version is available.

Generated by OpenCVE AI on April 29, 2026 at 16:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 23 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daman Jeet Finale Lite finale-woocommerce-sales-countdown-timer-discount allows Reflected XSS.This issue affects Finale Lite: from n/a through <= 2.20.0.
Title WordPress Finale Lite Plugin <= 2.20.0 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T19:01:31.279Z

Reserved: 2025-06-19T10:02:39.648Z

Link: CVE-2025-52736

cve-icon Vulnrichment

Updated: 2025-10-23T14:01:56.518Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:43.713

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-52736

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T16:45:15Z

Weaknesses