Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dmccan Yada Wiki yada-wiki allows Stored XSS.This issue affects Yada Wiki: from n/a through <= 3.5.
Published: 2025-12-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in dmccan Yada Wiki allows stored XSS caused by inadequate neutralization of user input during page rendering. An attacker can save malicious scripts into plugin fields, which will then be embedded in the HTML output when a site visitor loads the affected page, potentially leading to phishing, credential theft or session hijacking. The weakness is a classic input validation flaw (CWE‑79).

Affected Systems

The flaw exists in all releases of the Yada Wiki WordPress plugin up to and including version 3.5. Administrators using versions through 3.5 are affected; newer releases (3.6 and beyond) are presumed free of the issue.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.5, indicating moderate severity. Its EPSS score is below 1 %, suggesting a low probability of widespread exploitation at present, and it is not listed in the CISA KEV catalog. Exploiting the vulnerability involves injecting malicious content into plugin data fields; this typically implies the need for permission to create or edit those fields, whereas the CVE does not explicitly confirm this requirement. Attackers can then trick legitimate site visitors into executing injected scripts when they view the affected pages.

Generated by OpenCVE AI on April 29, 2026 at 22:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Yada Wiki plugin to version 3.6 or later to eliminate the stored XSS flaw.
  • If an immediate upgrade is impossible, limit editing privileges for the plugin to trusted users and audit submitted content for suspicious script tags.
  • Deploy a web application firewall or similar content filtering layer to block or sanitize potentially dangerous payloads targeting the plugin’s input fields.

Generated by OpenCVE AI on April 29, 2026 at 22:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yada Wiki yada-wiki allows Stored XSS.This issue affects Yada Wiki: from n/a through 3.5. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dmccan Yada Wiki yada-wiki allows Stored XSS.This issue affects Yada Wiki: from n/a through <= 3.5.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 30 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Dec 2025 16:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yada Wiki yada-wiki allows Stored XSS.This issue affects Yada Wiki: from n/a through 3.5.
Title WordPress Yada Wiki plugin <= 3.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:16.334Z

Reserved: 2025-11-21T11:21:12.145Z

Link: CVE-2025-66094

cve-icon Vulnrichment

Updated: 2025-12-30T19:29:59.268Z

cve-icon NVD

Status : Deferred

Published: 2025-12-30T17:15:43.057

Modified: 2026-04-23T15:35:21.773

Link: CVE-2025-66094

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T22:15:16Z

Weaknesses