Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infomaniak Network VOD Infomaniak vod-infomaniak.This issue affects VOD Infomaniak: from n/a through <= 1.5.11.
Published: 2025-10-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation, classified as Cross‑Site Scripting. An attacker that can influence certain user‑generated fields can inject arbitrary JavaScript into pages rendered by the VOD Infomaniak plugin. When a victim opens the affected page, the injected script runs with the victim’s browser privileges, potentially enabling session hijacking, credential theft, or defacement. The flaw is a classic example of CWE‑79 and does not directly compromise the WordPress server or its database.

Affected Systems

The flaw is present in the Infomaniak Network VOD Infomaniak WordPress plugin for all releases up to and including version 1.5.11. Users running any of these plugin versions are affected, while newer releases are not reported to be vulnerable.

Risk and Exploitability

The CVSS score of 7.1 labels the issue as high severity, and the EPSS score of less than 1 % indicates a very low probability of exploitation under current observation. The flaw is not listed in CISA’s KEV catalog. Exploitation would likely occur over the public web interface of the plugin, requiring the victim to visit a crafted URL or trigger a form that includes malicious input. No authentication or privileged access is needed for the initial injection, making the attack vector remote.

Generated by OpenCVE AI on April 29, 2026 at 14:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the VOD Infomaniak plugin to the latest released version (≥ 1.5.12) to eliminate the XSS flaw.
  • If an upgrade cannot be performed immediately, disable any form fields or REST endpoints that accept untrusted input from the plugin until a patch is applied.
  • Audit the plugin’s output code to ensure all dynamic content is properly escaped for HTML context; implement output encoding for any remaining user‑controlled data.

Generated by OpenCVE AI on April 29, 2026 at 14:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Infomaniak
Infomaniak vod Infomaniak
Wordpress
Wordpress wordpress
Vendors & Products Infomaniak
Infomaniak vod Infomaniak
Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infomaniak Network VOD Infomaniak vod-infomaniak.This issue affects VOD Infomaniak: from n/a through <= 1.5.11.
Title WordPress VOD Infomaniak plugin <= 1.5.11 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Infomaniak Vod Infomaniak
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:47:41.781Z

Reserved: 2025-10-07T15:34:13.977Z

Link: CVE-2025-62020

cve-icon Vulnrichment

Updated: 2025-10-23T14:33:20.992Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:16:03.300

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-62020

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T14:15:14Z

Weaknesses