Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Genesis Club Lite genesis-club-lite allows Stored XSS.This issue affects Genesis Club Lite: from n/a through <= 1.17.
Published: 2025-09-22
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Genesis Club Lite plugin contains an improper neutralization of input during web page generation that allows attackers to store malicious scripts in the site. A successful exploitation leads to the execution of arbitrary JavaScript in the context of the website’s domain, which can be used to steal user credentials, hijack sessions, deface content, or redirect users to phishing sites. The flaw is a classic stored XSS that requires the attacker to craft input that will be rendered on subsequent page loads.

Affected Systems

The vulnerability applies to the Genesis Club Lite plugin developed by Russell Jamieson, affecting all releases from the start version up to and including 1.17. No specific sub‑versions are listed, so any installation of 1.17 or earlier is potentially affected.

Risk and Exploitability

With a CVSS score of 6.5, the issue is considered moderate severity. The EPSS score of less than 1 % indicates a very low likelihood of exploitation in the population, and the flaw is not currently referenced in CISA’s KEV catalog. The attack vector appears to be web‑based, requiring the attacker to persuade or trick a user into submitting data that is stored by the plugin and later reflected in site output. No publicly disclosed exploits are known, but the stored nature of the flaw means once injected, the malicious code can affect every site visitor until remediated.

Generated by OpenCVE AI on April 30, 2026 at 01:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Genesis Club Lite to a version newer than 1.17 or replace the plugin altogether
  • If an upgrade is not immediately possible, remove or disable any feature that accepts user‑supplied input until the issue is fixed
  • Deploy a WAF or input‑sanitization filter specifically targeting the Genesis Club Lite plugin’s input endpoints to block potential XSS payloads
  • Consult the plugin’s developer for a patch notice and keep abreast of any security advisories

Generated by OpenCVE AI on April 30, 2026 at 01:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30499 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Genesis Club Lite allows Stored XSS. This issue affects Genesis Club Lite: from n/a through 1.17.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Genesis Club Lite allows Stored XSS. This issue affects Genesis Club Lite: from n/a through 1.17. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Genesis Club Lite genesis-club-lite allows Stored XSS.This issue affects Genesis Club Lite: from n/a through <= 1.17.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 23 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Genesis Club Lite allows Stored XSS. This issue affects Genesis Club Lite: from n/a through 1.17.
Title WordPress Genesis Club Lite Plugin <= 1.17 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T01:04:11.099Z

Reserved: 2025-09-03T09:03:53.070Z

Link: CVE-2025-58691

cve-icon Vulnrichment

Updated: 2025-09-23T13:59:31.989Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:16:21.120

Modified: 2026-04-23T15:33:36.300

Link: CVE-2025-58691

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T02:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')