Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious delicious-recipes allows Stored XSS.This issue affects WP Delicious: from n/a through <= 1.8.7.
Published: 2025-09-03
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WP Delicious delivers persistent cross‑site scripting through stored input in the delicious-recipes plugin. An attacker who can insert content that the plugin stores without proper neutralization can cause arbitrary JavaScript to run in the browsers of any user who views the affected page. This flaw is classified as CWE‑79 and enables the execution of client‑side code, potentially leading to cookie theft, session hijacking or defacement of the site.

Affected Systems

The vulnerability exists in the WP Delicious delicious‑recipes plugin for WordPress. All versions from the earliest available release up through and including 1.8.7 are affected. Site administrators who are running WP Delicious on a WordPress installation should verify the plugin version and determine whether an upgrade is possible.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% shows that, as of this analysis, the likelihood of exploitation observed in the wild is low. The vulnerability is not listed in CISA’s KEV catalog. Attackers most likely would need the ability to submit content to the plugin or have a user context that can trigger the stored script. While the vulnerability can be abused without special privileges in many sites, the exact attack vector depends on whether the input entry point is exposed to unauthenticated users.

Generated by OpenCVE AI on April 30, 2026 at 02:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Delicious to the latest available version that removes the stored XSS flaw
  • If an upgrade is not immediately possible, restrict the plugin’s input fields to sanitised or whitelisted content, or block the problematic entry points via a temporary rule
  • Implement a strong Content Security Policy that disallows execution of inline scripts and restricts script sources

Generated by OpenCVE AI on April 30, 2026 at 02:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26561 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious allows Stored XSS. This issue affects WP Delicious: from n/a through 1.8.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious allows Stored XSS. This issue affects WP Delicious: from n/a through 1.8.7. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious delicious-recipes allows Stored XSS.This issue affects WP Delicious: from n/a through <= 1.8.7.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 03 Sep 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpdelicious
Wpdelicious wp Delicious
Vendors & Products Wordpress
Wordpress wordpress
Wpdelicious
Wpdelicious wp Delicious

Wed, 03 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Sep 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious allows Stored XSS. This issue affects WP Delicious: from n/a through 1.8.7.
Title WordPress WP Delicious Plugin <= 1.8.7 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Wpdelicious Wp Delicious
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:40:32.936Z

Reserved: 2025-09-03T09:02:38.119Z

Link: CVE-2025-58605

cve-icon Vulnrichment

Updated: 2025-09-03T17:38:17.784Z

cve-icon NVD

Status : Deferred

Published: 2025-09-03T15:15:42.000

Modified: 2026-04-23T15:33:26.857

Link: CVE-2025-58605

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T03:00:15Z

Weaknesses