Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ecommerce Platforms Gift Hunt gift-hunt allows Stored XSS.This issue affects Gift Hunt: from n/a through <= 2.0.2.
Published: 2025-12-24
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Gift Hunt plugin contains an Improper Neutralization of Input During Web Page Generation vulnerability that allows stored XSS. Improperly filtered input can be saved by the plugin and then displayed to other users without proper encoding. This flaw is classified as CWE‑79 and may enable a malicious actor to inject and execute arbitrary script code in the browsers of site visitors, leading to credential theft, session hijacking, defacement, or the delivery of further malware. The impact is an information disclosure and potential compromise of user sessions rather than direct system compromise.

Affected Systems

The vulnerability affects the Gift Hunt plugin for WordPress, version 2.0.2 and earlier. Validated product names include the "Gift Hunt" e‑commerce component. No specific operating system or server version is required; the flaw depends on the WordPress plugin code.

Risk and Exploitability

The CVSS score of 5.9 denotes moderate severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalogue. The likely attack vector requires an attacker to submit malicious input through a page or form that the plugin accepts and stores; the stored payload is then rendered to any page visitor. Although exploitation does not grant code execution on the server, the potential damage to user accounts and trust renders it a concern for sites that rely on the plugin for store operations.

Generated by OpenCVE AI on April 29, 2026 at 15:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Gift Hunt plugin to version 2.0.3 or later.
  • Apply the latest security release from the WordPress repository or official plugin source.
  • If an immediate upgrade is not possible, restrict or disable the plugin’s input fields that allow stored data and ensure client‑side input is sanitized before storage.

Generated by OpenCVE AI on April 29, 2026 at 15:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Ecommerce Platforms
Ecommerce Platforms gift Hunt
Wordpress
Wordpress wordpress
Vendors & Products Ecommerce Platforms
Ecommerce Platforms gift Hunt
Wordpress
Wordpress wordpress

Wed, 24 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 13:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ecommerce Platforms Gift Hunt gift-hunt allows Stored XSS.This issue affects Gift Hunt: from n/a through <= 2.0.2.
Title WordPress Gift Hunt plugin <= 2.0.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Ecommerce Platforms Gift Hunt
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:22.889Z

Reserved: 2025-12-09T16:46:50.745Z

Link: CVE-2025-67631

cve-icon Vulnrichment

Updated: 2025-12-24T18:55:03.965Z

cve-icon NVD

Status : Deferred

Published: 2025-12-24T13:16:19.310

Modified: 2026-04-27T18:16:47.577

Link: CVE-2025-67631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T15:30:14Z

Weaknesses