Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevstudio Easy Taxonomy Images easy-taxonomy-images allows Stored XSS.This issue affects Easy Taxonomy Images: from n/a through <= 1.0.1.
Published: 2026-02-20
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation that allows stored cross‑site scripting. Unsanitized data entered through Easy Taxonomy Images is persisted and later rendered on the public site without escaping, enabling an attacker to inject arbitrary JavaScript. It is inferred that the malicious script will be executed in the context of any visitor’s browser, potentially allowing the attacker to steal session cookies, hijack user sessions, redirect traffic, or display malicious content. Based on the description, it is inferred that a successful exploit requires the attacker to inject the malicious input, typically through administrative or content‑creation privileges within the plugin.

Affected Systems

The flaw exists in the wpdevstudio Easy Taxonomy Images plugin for WordPress versions up to and including 1.0.1. Any WordPress installation that has this plugin installed and has not upgraded beyond 1.0.1 is affected. The vulnerability is present in all build versions of the plugin from its earliest releases up to the last known vulnerable version.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high impact level. The EPSS score of less than 1% signals a very low probability that exploit code will be actively seen in the wild at present. The stored XSS nature of the flaw means that exploitation hinges on the attacker being able to inject malicious input that is later served to site visitors; this typically requires administrative access or content‑author privileges. It is inferred that a public exploit would need the attacker to have the ability to create or edit taxonomy image data, which is not broadly available to general public users. The vulnerability is not listed in CISA’s KEV catalog. When the conditions are met, the script runs client‑side and bypasses server‑side defenses, potentially compromising the confidentiality, integrity, and availability of affected sites.

Generated by OpenCVE AI on April 29, 2026 at 17:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Easy Taxonomy Images to the latest available version (e.g., 1.0.2 or newer; verify the release notes for a fix).
  • If an upgraded version is not yet available, disable or delete the plugin to remove the XSS vector entirely.
  • Sanitize existing taxonomy image entries by removing any embedded scripts or malicious content before re‑enabling the plugin or publishing new content.

Generated by OpenCVE AI on April 29, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpdevstudio
Wpdevstudio easy Taxonomy Images
Vendors & Products Wordpress
Wordpress wordpress
Wpdevstudio
Wpdevstudio easy Taxonomy Images

Fri, 20 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevstudio Easy Taxonomy Images easy-taxonomy-images allows Stored XSS.This issue affects Easy Taxonomy Images: from n/a through <= 1.0.1.
Title WordPress Easy Taxonomy Images plugin <= 1.0.1 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
Wpdevstudio Easy Taxonomy Images
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T19:11:36.173Z

Reserved: 2025-06-27T10:28:03.500Z

Link: CVE-2025-53231

cve-icon Vulnrichment

Updated: 2026-02-23T22:02:52.647Z

cve-icon NVD

Status : Deferred

Published: 2026-02-20T16:22:01.937

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-53231

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T17:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')