Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson AuthorSure authorsure allows Stored XSS.This issue affects AuthorSure: from n/a through <= 2.3.
Published: 2025-09-22
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation allows an attacker to inject malicious scripts that are stored and subsequently displayed to site visitors. The stored XSS flaw can run arbitrary JavaScript in the context of users who view author information, potentially exposing sensitive data, hijacking sessions, or defacing the site. This vulnerability affects the confidentiality and integrity of the site’s users and could lead to broader compromise if the attacker gains access to administrative functions.

Affected Systems

WordPress users who have installed the AuthorSure plugin from the Russell Jamieson vendor, versions up to and including 2.3, are impacted. This includes every version from the earliest release (unlisted) through 2.3. No specific WordPress core version is required.

Risk and Exploitability

The CVSS score of 5.9 classifies the issue as moderate severity, and the EPSS score being less than 1% indicates a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires the ability to submit or modify author information through the plugin’s interface; otherwise the attack vector is limited to users who are able to influence content entry. Once the script is stored, it executes in the browsers of anyone who views the affected author page, allowing attackers to steal credentials, deface content, or perform other malicious actions.

Generated by OpenCVE AI on April 30, 2026 at 00:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AuthorSure plugin to a version newer than 2.3, which addresses the XSS flaw.
  • If an upgrade is not immediately available, deactivate or delete the AuthorSure plugin to remove the vulnerable code from the site.
  • If the plugin cannot be removed, restrict write permissions to author information so that only trusted administrators can modify author profiles, thereby limiting the attacker’s ability to inject malicious input.

Generated by OpenCVE AI on April 30, 2026 at 00:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30669 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson AuthorSure allows Stored XSS. This issue affects AuthorSure: from n/a through 2.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson AuthorSure allows Stored XSS. This issue affects AuthorSure: from n/a through 2.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson AuthorSure authorsure allows Stored XSS.This issue affects AuthorSure: from n/a through <= 2.3.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Thu, 25 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson AuthorSure allows Stored XSS. This issue affects AuthorSure: from n/a through 2.3.
Title WordPress AuthorSure Plugin <= 2.3 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:39.771Z

Reserved: 2025-08-22T11:37:13.320Z

Link: CVE-2025-57979

cve-icon Vulnrichment

Updated: 2025-09-25T13:53:48.326Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:15:57.850

Modified: 2026-04-23T15:33:10.293

Link: CVE-2025-57979

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T01:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')