Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ex-Themes WooTour woo-tour allows Reflected XSS.This issue affects WooTour: from n/a through <= 3.6.3.
Published: 2025-11-06
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user input in the Ex‑Themes WooTour WordPress plugin allows attackers to inject malicious JavaScript that is reflected back to the browser. The reflected XSS flaw can be triggered by entering crafted data into plugin‑provided fields or URLs, enabling attackers to obtain cookies, hijack sessions, or execute arbitrary scripts in the victim’s context. This vulnerability is classified under CWE‑79, which denotes cross‑site scripting weakness.

Affected Systems

WordPress sites that have the WooTour plugin from Ex‑Themes installed are affected. The flaw exists in all supported versions from the earliest release up to and including 3.6.3, with no specific older release information available. Site owners should verify which version is running and prepare to apply a fix.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high impact for remote attackers who can supply input. However, the EPSS score is below 1 %, suggesting a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need to entice a victim to visit a crafted URL or interact with a vulnerable input field, which is typically user‑initiated, making exploitation possible but not trivial.

Generated by OpenCVE AI on April 29, 2026 at 23:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WooTour plugin to the latest available version, which removes the XSS flaw.
  • If an immediate update is not possible, disable the plugin or remove any features that accept unsanitized user input on the affected site.
  • Deploy or configure a web application firewall to block reflected XSS payloads and monitor for suspicious script injections.

Generated by OpenCVE AI on April 29, 2026 at 23:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Fri, 07 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 06 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ex-Themes WooTour woo-tour allows Reflected XSS.This issue affects WooTour: from n/a through <= 3.6.3.
Title WordPress WooTour plugin <= 3.6.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:35.855Z

Reserved: 2025-07-28T10:56:24.796Z

Link: CVE-2025-54722

cve-icon Vulnrichment

Updated: 2025-11-06T16:27:15.767Z

cve-icon NVD

Status : Deferred

Published: 2025-11-06T16:15:58.277

Modified: 2026-04-27T16:16:29.060

Link: CVE-2025-54722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T23:30:22Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')