Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vernon Systems Limited eHive Search ehive-search allows Reflected XSS.This issue affects eHive Search: from n/a through <= 2.5.0.
Published: 2026-01-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Upgrade
AI Analysis

Impact

This vulnerability is an improper neutralization of input that allows a reflected cross‑site scripting (XSS) attack. An attacker who succeeds can inject malicious scripts that run in a victim’s browser when they access the eHive Search plugin, potentially leading to session hijacking, credential theft, or defacement. The weakness is classified as CWE‑79, which focuses on unintended script execution via reflected user input.

Affected Systems

Vendors etc. The affected product is eHive Search by Vernon Systems Limited. Versions up through and including 2.5.0 are vulnerable. Any deployment running 2.5.0 or earlier is at risk.

Risk and Exploitability

The CVSS v3.1 score of 7.1 indicates a high severity of this vulnerability. The EPSS score is less than 1 %, suggesting current exploitation activity is very low, and it is not listed in the CISA KEV catalog. The likely attack vector is via a crafted query string in a web request to the search functionality, where the plugin reflects user input back into the page without proper sanitization. An attacker would need the target site to load the vulnerable plugin and a user to visit the tampered URL to deliver malicious payloads.

Generated by OpenCVE AI on April 28, 2026 at 18:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the eHive Search plugin to a version newer than 2.5.0, which includes the XSS fix.
  • If an immediate upgrade is not possible, restrict the search functionality by sanitizing input or temporarily disabling the plugin until the update can be applied.
  • Deploy a web application firewall rule to block requests containing JavaScript payloads in the search query parameter, thereby reducing the attack surface.

Generated by OpenCVE AI on April 28, 2026 at 18:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 09 Jan 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 08 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Jan 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Thu, 08 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vernon Systems Limited eHive Search ehive-search allows Reflected XSS.This issue affects eHive Search: from n/a through <= 2.5.0.
Title WordPress eHive Search plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:23.760Z

Reserved: 2025-12-15T09:59:55.700Z

Link: CVE-2025-67930

cve-icon Vulnrichment

Updated: 2026-01-08T14:54:19.849Z

cve-icon NVD

Status : Deferred

Published: 2026-01-08T10:15:51.990

Modified: 2026-04-27T18:16:50.237

Link: CVE-2025-67930

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T18:30:37Z

Weaknesses