Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wayne Allen Postie postie allows Stored XSS.This issue affects Postie: from n/a through <= 1.9.73.
Published: 2025-12-31
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization of input in the Postie plugin allows a stored cross‑site scripting flaw. Malicious payloads that are submitted through the plugin can be stored and later rendered in web pages, enabling an attacker to execute arbitrary code in the browser of any user who views the affected content.

Affected Systems

The vulnerability affects the Postie plugin authored by Wayne Allen, versions up to and including 1.9.73. No other WordPress core or plugins are listed as affected.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% shows a low probability of exploitation at present. The flaw is not part of the CISA KEV catalogue. Based on the description, the likely attack vector involves submitting or editing content through the plugin’s form or email interface, which is then rendered in WordPress posts or pages. Exploitation would allow attacker‑controlled JavaScript to run in the context of users who view the compromised content, but the success depends on the attacker’s ability to provide input to the plugin and on users accessing the stored content.

Generated by OpenCVE AI on April 29, 2026 at 21:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest release of the Postie plugin (any version newer than 1.9.73) to remove the stored XSS vulnerability.
  • If an update cannot be performed immediately, sanitize or strip disallowed HTML tags from content processed by the plugin, or disable the plugin’s input handling for untrusted users.
  • Deploy a web‑application firewall rule or content‑security‑policy to detect and block common XSS attack patterns targeting the Postie plugin’s input fields.

Generated by OpenCVE AI on April 29, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wayne Allen Postie postie allows Stored XSS.This issue affects Postie: from n/a through 1.9.73. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wayne Allen Postie postie allows Stored XSS.This issue affects Postie: from n/a through <= 1.9.73.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wayne Allen
Wayne Allen postie
Wordpress
Wordpress wordpress
Vendors & Products Wayne Allen
Wayne Allen postie
Wordpress
Wordpress wordpress

Wed, 31 Dec 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 31 Dec 2025 13:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wayne Allen Postie postie allows Stored XSS.This issue affects Postie: from n/a through 1.9.73.
Title WordPress Postie plugin <= 1.9.73 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wayne Allen Postie
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:08.681Z

Reserved: 2025-10-24T14:25:44.112Z

Link: CVE-2025-63020

cve-icon Vulnrichment

Updated: 2025-12-31T14:00:13.165Z

cve-icon NVD

Status : Deferred

Published: 2025-12-31T14:15:54.083

Modified: 2026-04-23T15:34:58.113

Link: CVE-2025-63020

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T22:00:07Z

Weaknesses