Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy Sessions sessions allows Stored XSS.This issue affects Sessions: from n/a through <= 3.2.0.
Published: 2025-08-22
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization of input during web page generation allows malicious JavaScript to be stored in the Sessions plugin and later rendered when a page is loaded. The vulnerability is a stored XSS flaw that can be exploited by injecting script code into a data field that the plugin processes and persists, leading to cross‑site scripting when the content is displayed to users. The potential impact includes theft of session cookies or other sensitive data, defacement of content, and execution of arbitrary actions in the context of the victim’s browser.

Affected Systems

The Sessions plugin by Pierre Lannoy is affected when its version is 3.2.0 or earlier. The vulnerability applies to any WordPress installation that has the plugin installed and uses the vulnerable versions.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate severity level. The EPSS score of less than 1% suggests that the likelihood of exploitation in the wild is currently very low, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a stored input field within the plugin’s administration interface; an attacker who can submit data will have that script executed for every user who views the affected page. No special conditions are required beyond having the vulnerable plugin active.

Generated by OpenCVE AI on April 30, 2026 at 03:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Sessions plugin to version 3.2.1 or later to eliminate the stored XSS flaw.
  • If an immediate update is not possible, remove or disable any input fields that allow user‑supplied data to be saved by the plugin until the patch is applied.
  • Consider implementing a web application firewall rule to block or sanitize scripts in the bot traffic that targets the Sessions plugin.
  • If the plugin is not essential, uninstall it completely to avoid the risk altogether.

Generated by OpenCVE AI on April 30, 2026 at 03:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28649 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy Sessions allows Stored XSS. This issue affects Sessions: from n/a through 3.2.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy Sessions allows Stored XSS. This issue affects Sessions: from n/a through 3.2.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy Sessions sessions allows Stored XSS.This issue affects Sessions: from n/a through <= 3.2.0.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Sat, 23 Aug 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 22 Aug 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 22 Aug 2025 12:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy Sessions allows Stored XSS. This issue affects Sessions: from n/a through 3.2.0.
Title WordPress Sessions Plugin <= 3.2.0 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:35:01.722Z

Reserved: 2025-08-22T11:35:36.401Z

Link: CVE-2025-57890

cve-icon Vulnrichment

Updated: 2025-08-22T13:00:33.633Z

cve-icon NVD

Status : Deferred

Published: 2025-08-22T12:15:32.470

Modified: 2026-04-23T15:32:57.777

Link: CVE-2025-57890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T03:15:26Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')