Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Catch Themes Essential Widgets essential-widgets allows Stored XSS.This issue affects Essential Widgets: from n/a through <= 2.2.2.
Published: 2025-12-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Catch Themes Essential Widgets versions up to 2.2.2 contain a stored cross‑site scripting flaw that allows input to be stored in the database and rendered without proper neutralization. An attacker who can inject malicious script will trigger execution in a victim’s browser when a page containing the widget is viewed, enabling cookie theft, session hijacking, or webpage defacement. The vulnerability is a classic input validation issue identified as CWE‑79 and is rated with a CVSS score of 6.5, indicating moderate severity. The impact is that any user who views the affected page could be compromised, potentially exposing personal data or credentials.

Affected Systems

The flaw affects the Catch Themes Essential Widgets plugin for WordPress, both free and pro editions, on all versions from the earliest release through 2.2.2. No further version restrictions are provided, so all installations of this plugin prior to the next release are vulnerable.

Risk and Exploitability

The EPSS score is below 1 %, showing a low estimated exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the flaw allows persistent script injection via stored data, the potential damage is significant. The attack vector is client‑side; an attacker must first inject malicious content that is stored by the plugin, typically through interacting with an input field that is later rendered on a page. Inference suggests that administrative privileges or at least access to widget configuration are required, but the exact permissions needed are not specified in the description.

Generated by OpenCVE AI on April 29, 2026 at 11:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Catch Themes Essential Widgets to the latest version that includes the patch for the stored XSS flaw.
  • If an upgrade is not immediately possible, remove or disable any widgets that accept arbitrary user input, or configure them to store only plain text to prevent script execution.
  • Ensure that WordPress core and all other plugins are kept up to date to reduce the overall attack surface.

Generated by OpenCVE AI on April 29, 2026 at 11:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 12 Jan 2026 13:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:catchthemes:essential_widgets:*:*:*:*:*:wordpress:*:* cpe:2.3:a:catchthemes:essential_widgets:*:*:*:*:free:wordpress:*:*
cpe:2.3:a:catchthemes:essential_widgets:*:*:*:*:pro:wordpress:*:*

Mon, 12 Jan 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Catchthemes
Catchthemes essential Widgets
CPEs cpe:2.3:a:catchthemes:essential_widgets:*:*:*:*:*:wordpress:*:*
Vendors & Products Catchthemes
Catchthemes essential Widgets

Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 09 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Catch Themes Essential Widgets essential-widgets allows Stored XSS.This issue affects Essential Widgets: from n/a through <= 2.2.2.
Title WordPress Essential Widgets plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Catchthemes Essential Widgets
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T19:18:54.458Z

Reserved: 2025-12-09T12:21:12.170Z

Link: CVE-2025-67543

cve-icon Vulnrichment

Updated: 2025-12-09T19:45:10.949Z

cve-icon NVD

Status : Modified

Published: 2025-12-09T16:18:29.913

Modified: 2026-01-20T15:19:19.380

Link: CVE-2025-67543

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T11:45:10Z

Weaknesses