Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designinvento DirectoryPress directorypress allows DOM-Based XSS.This issue affects DirectoryPress: from n/a through <= 3.6.25.
Published: 2025-10-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The DirectoryPress plugin for WordPress contains an improper neutralization of input during web page generation, allowing DOM-based cross‑site scripting (XSS). This flaw corresponds to CWE‑79, Improper Neutralization of Input During Web Page Generation. This flaw lets an attacker inject malicious JavaScript into a page viewed by other users, which can be used to hijack sessions, steal cookies, deface content, or execute arbitrary commands in the context of the website. The vulnerability affects the plugin up to version 3.6.25 and poses a moderate to high risk due to the potential for widespread impact on any user interacting with the affected pages.

Affected Systems

Designinvento DirectoryPress, a WordPress plugin available up to and including version 3.6.25. Any WordPress installation that uses this plugin version is susceptible.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate priority for remediation, while the EPSS score of less than 1% suggests the likelihood of exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remotely via the Web interface of a WordPress site; an attacker can craft a URL or form input that the plugin outputs without proper sanitization, triggering the DOM-based XSS. No additional prerequisites are stated, but the flaw requires a user to receive the malicious page, making it a typical web‑based XSS attack.

Generated by OpenCVE AI on April 29, 2026 at 16:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade DirectoryPress to a version newer than 3.6.25, which resolves the CWE‑79 input validation flaw.
  • Configure a Content Security Policy that restricts script execution to trusted sources and disallows inline scripts.
  • Deploy a web application firewall or security plugin that filters or blocks malicious input targeting the DirectoryPress plugin.

Generated by OpenCVE AI on April 29, 2026 at 16:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designinvento DirectoryPress directorypress allows DOM-Based XSS.This issue affects DirectoryPress: from n/a through <= 3.6.25. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designinvento DirectoryPress directorypress allows DOM-Based XSS.This issue affects DirectoryPress: from n/a through <= 3.6.25.

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Designinvento
Designinvento directorypress
Wordpress
Wordpress wordpress
Vendors & Products Designinvento
Designinvento directorypress
Wordpress
Wordpress wordpress

Mon, 27 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Oct 2025 02:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designinvento DirectoryPress directorypress allows DOM-Based XSS.This issue affects DirectoryPress: from n/a through <= 3.6.25.
Title WordPress DirectoryPress plugin <= 3.6.25 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Designinvento Directorypress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:58:36.202Z

Reserved: 2025-10-24T14:25:01.200Z

Link: CVE-2025-62967

cve-icon Vulnrichment

Updated: 2025-10-27T15:05:52.928Z

cve-icon NVD

Status : Deferred

Published: 2025-10-27T02:15:57.073

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-62967

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T16:30:15Z

Weaknesses