Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Content Rock Convert rock-convert allows Stored XSS.This issue affects Rock Convert: from n/a through <= 3.0.1.
Published: 2025-10-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input that allows stored cross‑site scripting in the Rock Convert plugin for WordPress. The flaw lets an attacker inject malicious scripts that are rendered when the page is viewed. It is inferred from the nature of stored XSS that an attacker might be able to steal cookies, hijack sessions, or perform other client‑side attacks, although the official notice does not explicitly describe these outcomes. No further attack consequences are described in the official notice, but the stored nature means the code persists in the website content.

Affected Systems

The affected product is the Rock Content Rock Convert WordPress plugin, versions up through 3.0.1. Any WordPress site that has an installed copy of this plugin prior to version 3.0.2 is vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate risk level. The EPSS score of less than 1% suggests that exploitation is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is web‑based; it is inferred that the flaw can be exploited by an attacker who can inject content into the plugin’s input fields and later cause that content to be displayed on the site. Because this is stored XSS, exploitation does not require user interaction beyond loading the affected page.

Generated by OpenCVE AI on April 30, 2026 at 05:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Rock Convert plugin to a version newer than 3.0.1.
  • If an update cannot be performed immediately, disable or uninstall the plugin until a patch is available.
  • Limit the use of the plugin to users with administrative privileges or otherwise ensure that any content processed by the plugin is sanitized before display.

Generated by OpenCVE AI on April 30, 2026 at 05:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Tue, 28 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Rockcontent
Rockcontent rock Convert
Wordpress
Wordpress wordpress
Vendors & Products Rockcontent
Rockcontent rock Convert
Wordpress
Wordpress wordpress

Mon, 27 Oct 2025 02:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Content Rock Convert rock-convert allows Stored XSS.This issue affects Rock Convert: from n/a through <= 3.0.1.
Title WordPress Rock Convert plugin <= 3.0.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Rockcontent Rock Convert
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:05.684Z

Reserved: 2025-10-24T14:24:30.143Z

Link: CVE-2025-62911

cve-icon Vulnrichment

Updated: 2025-10-27T15:17:30.572Z

cve-icon NVD

Status : Deferred

Published: 2025-10-27T02:15:50.560

Modified: 2026-04-27T18:16:29.873

Link: CVE-2025-62911

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T05:30:06Z

Weaknesses