Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious delicious-recipes allows DOM-Based XSS.This issue affects WP Delicious: from n/a through <= 1.8.4.
Published: 2025-07-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user‑supplied input in the WP Delicious plugin allows a DOM‑based cross‑site scripting attack, enabling an attacker to inject malicious JavaScript into the browser context of anyone who interacts with affected content. This flaw corresponds to CWE‑79 and can lead to client‑side code execution, defacement, cookie theft or session hijacking, compromising the confidentiality and integrity of the user environment. The vulnerability is triggered when the plugin processes unsanitized input during web page generation, resulting in script execution within the victim’s browser.

Affected Systems

All installations of the WordPress WP Delicious plugin up to and including version 1.8.4 are affected. No other versions or products are listed.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.5, indicating moderate severity, and an EPSS of less than 1%, suggesting a low probability of exploitation at the time of analysis. It is not listed in the CISA KEV catalog. Exploitation requires that an end user visit a crafted URL or otherwise interact with vulnerable input fields hosted by the plugin, making it a user‑interaction attack. Once triggered, malicious scripts run in the context of the victim’s browser, potentially allowing data theft or further web‑based attacks.

Generated by OpenCVE AI on April 30, 2026 at 09:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Delicious plugin to the latest available version that includes the XSS fix.
  • If an upgrade is not immediately possible, sanitize all user‑supplied data before rendering by applying proper output escaping routines consistent with web security best practices.
  • As a temporary countermeasure, remove or deactivate the WP Delicious plugin from the WordPress installation until a secure version is deployed.

Generated by OpenCVE AI on April 30, 2026 at 09:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-21672 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious allows DOM-Based XSS. This issue affects WP Delicious: from n/a through 1.8.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious allows DOM-Based XSS. This issue affects WP Delicious: from n/a through 1.8.4. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious delicious-recipes allows DOM-Based XSS.This issue affects WP Delicious: from n/a through <= 1.8.4.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 16 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00031}


Wed, 16 Jul 2025 10:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious allows DOM-Based XSS. This issue affects WP Delicious: from n/a through 1.8.4.
Title WordPress WP Delicious plugin <= 1.8.4 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:28.943Z

Reserved: 2025-07-16T08:51:50.628Z

Link: CVE-2025-54023

cve-icon Vulnrichment

Updated: 2025-07-16T19:58:36.552Z

cve-icon NVD

Status : Deferred

Published: 2025-07-16T11:15:29.870

Modified: 2026-04-23T15:32:43.220

Link: CVE-2025-54023

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T09:45:25Z

Weaknesses