Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thomas Harris Search Cloud One search-cloud-one allows Stored XSS.This issue affects Search Cloud One: from n/a through <= 2.2.5.
Published: 2025-09-05
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation in Thomas Harris's Search Cloud One plugin allows malicious script code to be stored and subsequently rendered in the site’s content, resulting in a stored XSS condition. This flaw is identified as CWE‑79 and can potentially enable an attacker to inject scripts that execute whenever a visitor loads the affected page, possibly allowing session hijacking, defacement of content, or delivery of phishing payloads. The typical XSS consequences are documented, but the specific impact would depend on the exploitation context.

Affected Systems

The Search Cloud One plugin for WordPress, supplied by Thomas Harris, is vulnerable in all releases from the first unknown version up to and including 2.2.5. Versions newer than 2.2.5 are presumed fixed unless the vendor’s changelog indicates otherwise.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate severity, while an EPSS score below 1% shows a very low probability of mass exploitation at present. The vulnerability is not recorded in the CISA KEV catalog, suggesting it has not yet been widely exploited. Attackers would need to supply crafted input via the plugin’s user interface, which is stored and later rendered unsanitized in the site; once a payload is present, it remains effective until the plugin is updated or the malicious data is removed. The likely attack vector involves an authenticated or unauthenticated user entering malicious code into a search‑related field that is then displayed on the front‑end.

Generated by OpenCVE AI on April 30, 2026 at 07:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Search Cloud One plugin to any release newer than 2.2.5 to apply the vendor’s fix.
  • If an upgrade cannot be performed immediately, disable or uninstall the plugin to eliminate the possibility of serving stored malicious content.
  • Apply server‑side input validation and output encoding to the plugin’s search interfaces as a temporary mitigation until the official patch is applied.

Generated by OpenCVE AI on April 30, 2026 at 07:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26895 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thomas Harris Search Cloud One allows Stored XSS. This issue affects Search Cloud One: from n/a through 2.2.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thomas Harris Search Cloud One allows Stored XSS. This issue affects Search Cloud One: from n/a through 2.2.5. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thomas Harris Search Cloud One search-cloud-one allows Stored XSS.This issue affects Search Cloud One: from n/a through <= 2.2.5.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Sun, 07 Sep 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 05 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Sep 2025 14:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thomas Harris Search Cloud One allows Stored XSS. This issue affects Search Cloud One: from n/a through 2.2.5.
Title WordPress Search Cloud One Plugin <= 2.2.5 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:49.055Z

Reserved: 2025-09-05T10:50:25.872Z

Link: CVE-2025-58883

cve-icon Vulnrichment

Updated: 2025-09-05T14:30:55.929Z

cve-icon NVD

Status : Deferred

Published: 2025-09-05T14:16:05.700

Modified: 2026-06-17T09:45:13.883

Link: CVE-2025-58883

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T07:15:31Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')