Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Stored XSS.This issue affects DELUCKS SEO: from n/a through <= 2.7.0.
Published: 2025-09-22
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Stored Cross‑Site Scripting (XSS) occurs when user input is not properly neutralized before being saved and later displayed in web pages, allowing attackers to inject malicious scripts. In this case, the DELUCKS SEO plugin fails to escape data persisted by the plugin, enabling stored XSS. An attacker who can submit input to the plugin can have the malicious script executed in the browsers of any site visitor, leading to possible session hijacking, credential theft, defacement, or delivery of further malware. This weakness corresponds to CWE‑79.

Affected Systems

Any installation of the DELUCKS SEO plugin, regardless of the surrounding WordPress version, up to and including version 2.7.0, is affected. The issue is documented for all versions from the plugin’s earliest release through 2.7.0.

Risk and Exploitability

The CVSS base score of 6.5 indicates a moderate risk to confidentiality, integrity, and availability. The EPSS score of less than 1% suggests that actual exploitation attempts are currently rare, and the vulnerability is not listed in the CISA KEV catalog. Likely attack paths involve entering malicious payloads through the plugin’s administrative settings or data entry fields, which are then rendered without escaping when the content is displayed on the front‑end. Because the flaw is stored, an attacker can maintain persistence until the affected content is viewed by end users. Detection would rely on monitoring for unusual script injections or anomalous behavior in visitors’ browsers.

Generated by OpenCVE AI on April 30, 2026 at 06:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the DELUCKS SEO plugin to the latest version, preferably 2.8.0 or newer, where stored XSS has been fixed.
  • If updating is not immediately possible, remove the plugin or restrict access to its admin interface to trusted users only to prevent injection.
  • Deploy a Web Application Firewall rule that blocks or sanitizes input containing typical XSS patterns before it reaches the plugin’s storage.
  • Perform a site‑wide scan for injected script tags in plugin data and clean any malicious content manually.

Generated by OpenCVE AI on April 30, 2026 at 06:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30740 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SEO allows Stored XSS. This issue affects DELUCKS SEO: from n/a through 2.7.0.
History

Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Stored XSS.This issue affects DELUCKS SEO: from n/a through <= 2.7.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Stored XSS.This issue affects DELUCKS SEO: from n/a through <= 2.7.0.
Title WordPress DELUCKS SEO plugin <= 2.7.2 - Cross Site Scripting (XSS) vulnerability WordPress DELUCKS SEO Plugin <= 2.7.0 - Cross Site Scripting (XSS) Vulnerability

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Stored XSS.This issue affects DELUCKS SEO: from n/a through <= 2.7.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Stored XSS.This issue affects DELUCKS SEO: from n/a through <= 2.7.2.
Title WordPress DELUCKS SEO Plugin <= 2.7.0 - Cross Site Scripting (XSS) Vulnerability WordPress DELUCKS SEO plugin <= 2.7.2 - Cross Site Scripting (XSS) vulnerability
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SEO allows Stored XSS. This issue affects DELUCKS SEO: from n/a through 2.7.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Stored XSS.This issue affects DELUCKS SEO: from n/a through <= 2.7.0.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Delucks
Delucks delucks Seo
Wordpress
Wordpress wordpress
Vendors & Products Delucks
Delucks delucks Seo
Wordpress
Wordpress wordpress

Tue, 23 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 22 Sep 2025 18:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SEO allows Stored XSS. This issue affects DELUCKS SEO: from n/a through 2.7.0.
Title WordPress DELUCKS SEO Plugin <= 2.7.0 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Delucks Delucks Seo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:26.664Z

Reserved: 2025-07-03T14:51:06.793Z

Link: CVE-2025-53570

cve-icon Vulnrichment

Updated: 2025-09-23T13:46:02.834Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:15:44.597

Modified: 2026-04-28T19:33:43.613

Link: CVE-2025-53570

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T06:30:29Z

Weaknesses