Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka leyka allows DOM-Based XSS.This issue affects Leyka: from n/a through <= 3.32.1.
Published: 2025-06-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the VaultDweller Leyka WordPress plugin is a DOM‑based Cross‑Site Scripting flaw that allows attackers to inject arbitrary JavaScript into the pages generated by the plugin. If an attacker succeeds in delivering malicious script, it can execute in the victim’s browser, leading to potential defacement of the site, theft of user session data, or the execution of further payloads without the user’s consent.

Affected Systems

This flaw affects all installations of the Leyka plugin version 3.32.1 and older. WordPress sites that have not upgraded beyond that release are susceptible, whether they are single‑user blogs or more complex multi‑user configurations.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1 % suggests a low probability of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalog. Because the vulnerability is DOM‑based, the likely attack vector would involve a user opening a page that relies on untrusted input from the Leyka plugin; during that rendering, malicious code could be executed. In the absence of an exploit that bypasses the low likelihood, the practical risk remains low, but the impact of a successful attack can be significant due to the ability to run user‑supplied scripts.

Generated by OpenCVE AI on April 30, 2026 at 10:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Leyka WordPress plugin to a version newer than 3.32.1, ensuring the latest security patches are applied.
  • If custom fields or widgets from the plugin remain, remove or replace them to eliminate the untrusted input source present in older releases.
  • Implement a strict Content‑Security‑Policy that restricts script sources, which helps mitigate the impact of any residual XSS risk.

Generated by OpenCVE AI on April 30, 2026 at 10:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19403 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka allows DOM-Based XSS. This issue affects Leyka: from n/a through 3.31.9.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka allows DOM-Based XSS. This issue affects Leyka: from n/a through 3.31.9. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka leyka allows DOM-Based XSS.This issue affects Leyka: from n/a through <= 3.32.1.
Title WordPress Leyka plugin <= 3.31.9 - Cross Site Scripting (XSS) Vulnerability WordPress Leyka plugin <= 3.32.1 - Cross Site Scripting (XSS) vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 27 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Jun 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka allows DOM-Based XSS. This issue affects Leyka: from n/a through 3.31.9.
Title WordPress Leyka plugin <= 3.31.9 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:22.820Z

Reserved: 2025-06-27T11:58:42.673Z

Link: CVE-2025-53275

cve-icon Vulnrichment

Updated: 2025-06-27T14:34:57.507Z

cve-icon NVD

Status : Deferred

Published: 2025-06-27T14:15:48.383

Modified: 2026-04-23T15:32:24.443

Link: CVE-2025-53275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T10:15:34Z

Weaknesses