Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Curator.io Curator.io curatorio allows Stored XSS.This issue affects Curator.io: from n/a through <= 1.9.5.
Published: 2025-12-31
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Curator.io Curator.io curatorio suffers a stored cross‑site scripting (XSS) flaw that allows an attacker to inject malicious scripts into web pages rendered by the plugin. The vulnerability arises from improper neutralization of user‑supplied input during page generation, which is a typical example of CWE‑79. If successful, an attacker could execute arbitrary JavaScript in the browser of any user who views the affected content, leading to credential theft, session hijacking, defacement or further exploitation of the user environment.

Affected Systems

The flaw is present in all versions of the Curator.io Curator.io curatorio plugin up to and including version 1.9.5. WordPress sites that have installed this plugin and have not applied a later update are susceptible. No specific WordPress core or PHP version requirement is listed, so the vulnerability can affect any WordPress deployment running a vulnerable plugin.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity impact, while the EPSS score of less than 1% suggests a low probability of exploitation as of the last assessment. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector involves injecting malicious content through the plugin’s data entry mechanisms; however this is inferred from the stored XSS nature of the flaw and not explicitly stated in the advisory.

Generated by OpenCVE AI on April 29, 2026 at 18:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Curator.io Curator.io curatorio plugin to the latest version, which removes the XSS flaw.
  • If an upgrade cannot be performed immediately, disable or remove the plugin’s content creation and display features until a patched version is available.
  • As an interim countermeasure, sanitize all plugin‑output by applying WordPress’s esc_html or esc_url functions to any user input before rendering it, or replace the plugin with a trusted alternative that properly escapes output.
  • Install a web‑application firewall or security plugin that blocks script injection attempts on the site.

Generated by OpenCVE AI on April 29, 2026 at 18:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Curator.Io allows Stored XSS.This issue affects Curator.Io: from n/a through 1.9.5. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Curator.io Curator.io curatorio allows Stored XSS.This issue affects Curator.io: from n/a through <= 1.9.5.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Curator
Curator curator.io
Wordpress
Wordpress wordpress
Vendors & Products Curator
Curator curator.io
Wordpress
Wordpress wordpress

Wed, 31 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 31 Dec 2025 13:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Curator.Io allows Stored XSS.This issue affects Curator.Io: from n/a through 1.9.5.
Title WordPress Curator.io plugin <= 1.9.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Curator Curator.io
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:03.734Z

Reserved: 2025-10-21T14:59:44.294Z

Link: CVE-2025-62742

cve-icon Vulnrichment

Updated: 2025-12-31T15:05:42.737Z

cve-icon NVD

Status : Deferred

Published: 2025-12-31T13:15:41.813

Modified: 2026-04-23T15:34:39.510

Link: CVE-2025-62742

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T18:15:17Z

Weaknesses