Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Posts Display magical-posts-display allows DOM-Based XSS.This issue affects Magical Posts Display: from n/a through <= 1.2.52.
Published: 2025-08-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper sanitization of user‑supplied data when generating HTML content in the Magical Posts Display plugin. The flaw permits an attacker to inject arbitrary JavaScript into a page that is rendered by a victim’s browser. Because the script executes with the victim’s privileges, it can steal cookies, hijack sessions, deface the site, or redirect users to malicious destinations. The weakness corresponds to CWE‑79 and results in a moderate‑severity risk (CVSS 6.5).

Affected Systems

The flaw affects all installations of the Noor Alam Magical Posts Display WordPress plugin from any unspecified initial version up through 1.2.52 inclusive. Any site using this plugin version in a WordPress content‑management environment is potentially vulnerable.

Risk and Exploitability

Although the CVSS score indicates a moderate impact, the EPSS score of < 1% suggests that the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through user‑generated content or administrative input that is rendered by the plugin. An attacker can embed malicious code that will execute in the browser of anyone who views a page that includes the vulnerable plugin output, making it an easily triggered but client‑side attack that depends on victim interaction.

Generated by OpenCVE AI on April 30, 2026 at 03:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Magical Posts Display plugin to a version newer than 1.2.52, which removes the XSS vulnerability.
  • If an immediate update is not feasible, temporarily disable the plugin or remove all posts that might contain user‑controlled input until a patch is applied.
  • Review and sanitize any custom content that could be rendered by the plugin, ensuring that all user input is properly escaped before being sent to the browser.

Generated by OpenCVE AI on April 30, 2026 at 03:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-24688 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Posts Display allows DOM-Based XSS. This issue affects Magical Posts Display: from n/a through 1.2.52.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Posts Display allows DOM-Based XSS. This issue affects Magical Posts Display: from n/a through 1.2.52. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Posts Display magical-posts-display allows DOM-Based XSS.This issue affects Magical Posts Display: from n/a through <= 1.2.52.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Thu, 14 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 14 Aug 2025 10:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Posts Display allows DOM-Based XSS. This issue affects Magical Posts Display: from n/a through 1.2.52.
Title WordPress Magical Posts Display Plugin plugin <= 1.2.52 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:35.700Z

Reserved: 2025-07-28T10:56:09.194Z

Link: CVE-2025-54706

cve-icon Vulnrichment

Updated: 2025-08-14T13:48:36.271Z

cve-icon NVD

Status : Deferred

Published: 2025-08-14T11:15:53.120

Modified: 2026-04-23T15:32:51.730

Link: CVE-2025-54706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T03:30:27Z

Weaknesses