Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The African Boss Get Cash get-cash allows Stored XSS.This issue affects Get Cash: from n/a through <= 3.2.3.
Published: 2025-09-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Neutralization of Input During Web Page Generation in The African Boss Get Cash plugin (versions up to 3.2.3) allows an attacker to store malicious JavaScript in the plugin's database entries. When the plugin renders these entries, the unsanitized input is executed as script in the browser, resulting in a stored XSS flaw. The vulnerability arises from a lack of output encoding (CWE-79) and can be triggered by inserting crafted data into any input that is later displayed to site visitors.

Affected Systems

All WordPress sites that have the African Boss Get Cash plugin version 3.2.3 or earlier are affected. The plugin processes user-supplied data (such as transaction details) and presents it in the front-end without sanitization. The flaw exists regardless of the WordPress core version, so sites of all sizes and hosts remain vulnerable.

Risk and Exploitability

The CVSS score of 6.5 denotes moderate severity, while an EPSS score of less than 1% indicates a low probability of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote: an attacker submits malicious payload via an input accepted by the Get Cash plugin; the payload is stored in the database and subsequently executed by any user viewing the affected page. Because the payload runs in the victim's browser, it can steal session cookies, deface the site, or redirect users to malicious sites.

Generated by OpenCVE AI on April 30, 2026 at 15:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Get Cash plugin to the latest version that contains the XSS fix.
  • If the update cannot be applied immediately, deactivate or remove the Get Cash plugin until the fix is available.
  • As a temporary workaround, enforce strict sanitization on all user-supplied fields by configuring WordPress's wp_kses function or installing a reputable security plugin that strips dangerous tags before rendering.

Generated by OpenCVE AI on April 30, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26954 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The African Boss Get Cash allows Stored XSS. This issue affects Get Cash: from n/a through 3.2.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The African Boss Get Cash allows Stored XSS. This issue affects Get Cash: from n/a through 3.2.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The African Boss Get Cash get-cash allows Stored XSS.This issue affects Get Cash: from n/a through <= 3.2.3.
Title WordPress Get Cash Plugin <= 3.2.2 - Cross Site Scripting (XSS) Vulnerability WordPress Get Cash plugin <= 3.2.3 - Cross Site Scripting (XSS) vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Mon, 08 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 07 Sep 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 05 Sep 2025 14:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The African Boss Get Cash allows Stored XSS. This issue affects Get Cash: from n/a through 3.2.2.
Title WordPress Get Cash Plugin <= 3.2.2 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:47.953Z

Reserved: 2025-09-05T10:49:34.050Z

Link: CVE-2025-58823

cve-icon Vulnrichment

Updated: 2025-09-08T15:03:58.688Z

cve-icon NVD

Status : Deferred

Published: 2025-09-05T14:15:54.070

Modified: 2026-04-23T15:33:42.190

Link: CVE-2025-58823

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T15:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')