Description
Improper Neutralization of Formula Elements in a CSV File vulnerability in Denis V (Artprima) AP HoneyPot WordPress Plugin ap-honeypot allows Reflected XSS.This issue affects AP HoneyPot WordPress Plugin: from n/a through <= 1.4.
Published: 2025-09-05
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper neutralization of formula elements in CSV files processed by the AP HoneyPot WordPress Plugin. An attacker can insert specially crafted script or formula content that is response encoded and later executed in a visitor's browser, resulting in reflected cross‑site scripting. This flaw enables an adversary to run arbitrary JavaScript in the context of the site, potentially stealing credentials, session cookies or defacing pages. It is classified under CWE‑1236, which signifies that user input is not correctly sanitized before being processed.

Affected Systems

The affected product is Denis V (Artprima) AP HoneyPot WordPress Plugin, any release whose version identifier is unknown or ≤1.4. WordPress sites employing this plugin, without upgrading beyond v1.4, are vulnerable. No other vendors or products are explicitly listed for this vulnerability.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high severity, while the EPSS score of <1% suggests that, as of now, exploitation is unlikely but not impossible. The vulnerability is not present in the CISA KEV catalog, which means it is not a known, actively exploited flaw. An attacker could target the plugin by uploading a malicious CSV file to the honeypot interface, or by tricking an authenticated user into submitting such a file. If the admin interface is publicly exposed, the attack path would be remote, requiring only the ability to access the upload form.

Generated by OpenCVE AI on April 30, 2026 at 02:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AP HoneyPot WordPress Plugin to any release newer than 1.4 as soon as a patched version is available.
  • If an upgrade cannot be performed immediately, temporarily disable or uninstall the plugin to eliminate the attack surface.
  • When the plugin must remain active, ensure that uploaded CSV files are sanitized by rejecting formula prefixes or enforcing server‑side validation that strips script‑like content before processing.

Generated by OpenCVE AI on April 30, 2026 at 02:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26922 Improper Neutralization of Formula Elements in a CSV File vulnerability in Denis V (Artprima) AP HoneyPot WordPress Plugin allows Reflected XSS. This issue affects AP HoneyPot WordPress Plugin: from n/a through 1.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Formula Elements in a CSV File vulnerability in Denis V (Artprima) AP HoneyPot WordPress Plugin allows Reflected XSS. This issue affects AP HoneyPot WordPress Plugin: from n/a through 1.4. Improper Neutralization of Formula Elements in a CSV File vulnerability in Denis V (Artprima) AP HoneyPot WordPress Plugin ap-honeypot allows Reflected XSS.This issue affects AP HoneyPot WordPress Plugin: from n/a through <= 1.4.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 05 Sep 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Sep 2025 14:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Formula Elements in a CSV File vulnerability in Denis V (Artprima) AP HoneyPot WordPress Plugin allows Reflected XSS. This issue affects AP HoneyPot WordPress Plugin: from n/a through 1.4.
Title WordPress AP HoneyPot WordPress Plugin Plugin <= 1.4 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-1236
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-13T00:19:38.448Z

Reserved: 2025-09-05T10:49:57.446Z

Link: CVE-2025-58855

cve-icon Vulnrichment

Updated: 2025-09-05T19:49:57.870Z

cve-icon NVD

Status : Deferred

Published: 2025-09-05T14:16:00.170

Modified: 2026-04-23T15:33:46.053

Link: CVE-2025-58855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T02:15:25Z

Weaknesses