Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik-privacy-policy oik-privacy-policy allows Reflected XSS.This issue affects oik-privacy-policy: from n/a through <= 1.4.10.
Published: 2025-10-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The oik‑privacy‑policy plugin for WordPress, versions up to and including 1.4.10, contains an improper neutralization of user input bug that allows a reflected cross‑site scripting (XSS) attack. By crafting a URL or form entry containing malicious script, an attacker can cause the plugin to echo that input back into an HTML context without proper escaping. This enables arbitrary JavaScript to run in the victim's browser, potentially hijacking sessions, defacing the site, or delivering phishing content. The vulnerability is a classic reflected XSS flaw tied to CWE‑79 and impacts the confidentiality, integrity, and availability of the affected web application from the perspective of its visitors.

Affected Systems

The affected product is the WordPress plugin oik‑privacy‑policy, developed by bobbingwide. All releases from the earliest available version through plugin version 1.4.10 are vulnerable. WordPress sites that have installed or are using any of those plugin versions are at risk.

Risk and Exploitability

The CVSS score of 7.1 places this vulnerability in the high‑severity range, indicating a significant potential impact if exploited. The EPSS score of less than 1% suggests that widespread exploitation is currently unlikely, but that does not eliminate the risk. This issue is not listed in the CISA KEV catalog, so there are no known widespread exploits in the public domain. The attack vector is clearly web‑based, requiring an attacker to supply malicious input via a URL or form that the plugin processes and reflects back. No additional privileges or authentication are needed to trigger the reflected XSS, and an active user session with the site can be compromised simply by visiting a crafted link.

Generated by OpenCVE AI on April 30, 2026 at 05:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the oik‑privacy‑policy plugin to the latest available version (>=1.4.11) where the XSS bug is fixed.
  • If an upgrade cannot be performed immediately, temporarily disable the oik‑privacy‑policy plugin until the fix is applied. This prevents the vulnerable code from running on the site.
  • Configure a web application firewall or content security policy to filter out or block malicious script input that targets the plugin’s reflected variables, adding an extra layer of protection while remediation is pending.

Generated by OpenCVE AI on April 30, 2026 at 05:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik-privacy-policy oik-privacy-policy allows Reflected XSS.This issue affects oik-privacy-policy: from n/a through <= 1.4.9. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik-privacy-policy oik-privacy-policy allows Reflected XSS.This issue affects oik-privacy-policy: from n/a through <= 1.4.10.
Title WordPress oik-privacy-policy Plugin <= 1.4.9 - Cross Site Scripting (XSS) Vulnerability WordPress oik-privacy-policy plugin <= 1.4.10 - Cross Site Scripting (XSS) vulnerability

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Bobbingwide
Bobbingwide oik
Wordpress
Wordpress wordpress
Vendors & Products Bobbingwide
Bobbingwide oik
Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik-privacy-policy oik-privacy-policy allows Reflected XSS.This issue affects oik-privacy-policy: from n/a through <= 1.4.9.
Title WordPress oik-privacy-policy Plugin <= 1.4.9 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References

Subscriptions

Bobbingwide Oik
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:17.997Z

Reserved: 2025-06-19T10:02:47.063Z

Link: CVE-2025-52743

cve-icon Vulnrichment

Updated: 2025-10-23T15:13:14.605Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:44.467

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-52743

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T05:45:16Z

Weaknesses