Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vadim Bogaiskov Bg Church Memos bg-church-memos allows DOM-Based XSS.This issue affects Bg Church Memos: from n/a through <= 1.1.
Published: 2025-09-22
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user input during page rendering in the Bg Church Memos plugin allows attackers to inject malicious JavaScript that executes in a victim’s browser. This DOM‑based XSS can lead to theft of session tokens, defacement of content, and the execution of arbitrary actions on behalf of the user. The flaw stems from a failure to sanitize input before embedding it into the page, a classic input validation weakness classified as CWE‑79.

Affected Systems

The vulnerability affects the WordPress Bg Church Memos plugin released by Vadim Bogaiskov. All installed copies with version 1.1 or earlier are susceptible. No other products or newer releases are listed as affected.

Risk and Exploitability

The CVSS score of 6.5 signals a moderate severity for a client‑side vulnerability. The EPSS score is less than 1%, indicating a low probability of widespread exploitation at present, and the issue is not yet listed in CISA’s KEV catalog. Attackers would exploit it by forcing a victim to load a crafted request that contains malicious script payloads; because the flaw is DOM‑based, it requires only the victim’s browser to execute the injected code. The risk is limited to the confidentiality, integrity, and availability of the victim’s interaction with the site but does not extend to server‑side compromise or privilege escalation.

Generated by OpenCVE AI on April 30, 2026 at 01:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Bg Church Memos plugin to a version newer than 1.1 to eliminate the vulnerable code path.
  • If an official upgrade is not immediately available, remove or deactivate the plugin to stop the XSS vector.
  • Perform a thorough scan of the site for any injected scripts or malicious code and clean them to ensure no remnants remain.

Generated by OpenCVE AI on April 30, 2026 at 01:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30589 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vadim Bogaiskov Bg Church Memos allows DOM-Based XSS. This issue affects Bg Church Memos: from n/a through 1.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vadim Bogaiskov Bg Church Memos allows DOM-Based XSS. This issue affects Bg Church Memos: from n/a through 1.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vadim Bogaiskov Bg Church Memos bg-church-memos allows DOM-Based XSS.This issue affects Bg Church Memos: from n/a through <= 1.1.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 23 Sep 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Vadim Bogaiskov
Vadim Bogaiskov bg Church Memos
Wordpress
Wordpress wordpress
Vendors & Products Vadim Bogaiskov
Vadim Bogaiskov bg Church Memos
Wordpress
Wordpress wordpress

Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vadim Bogaiskov Bg Church Memos allows DOM-Based XSS. This issue affects Bg Church Memos: from n/a through 1.1.
Title WordPress Bg Church Memos Plugin <= 1.1 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Vadim Bogaiskov Bg Church Memos
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:42.778Z

Reserved: 2025-08-27T16:19:44.958Z

Link: CVE-2025-58242

cve-icon Vulnrichment

Updated: 2025-09-23T15:57:41.486Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:16:09.860

Modified: 2026-04-23T15:33:22.147

Link: CVE-2025-58242

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T01:30:24Z

Weaknesses