Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes Listeo Core listeo-core allows Reflected XSS.This issue affects Listeo Core: from n/a through < 2.0.19.
Published: 2026-01-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

Improper neutralization of user input in the Listeo Core plugin allows reflected Cross‑Site Scripting (CWE‑79). The plugin echoes data from query parameters or form fields directly into the browser without encoding, enabling malicious scripts to execute when a victim visits a crafted page. The likely attack vector is a specially constructed URL or form input that reaches the plugin’s output surface, which an attacker can influence through social engineering or by directing a user to a malicious link.

Affected Systems

Purethemes Listeo Core is a WordPress plugin that provides directory and listing functionality. Versions from the initial release up to, but not including, 2.0.19 are affected. The plugin may be installed on any WordPress site that has not applied the update.

Risk and Exploitability

The CVSS base score of 7.1 indicates a moderate‑to‑high risk level, while the EPSS score of less than 1% suggests that, as of this analysis, exploitation attempts are unlikely to be observed in the wild. The vulnerability is not listed in CISA’s KEV catalog, which supports the assessment that no widespread exploitation campaigns have been documented. Based on the description, the attacker must be able to supply a crafted request that reaches the plugin’s output surface; once the payload is reflected in the browser, it executes with the privileges of the visiting user.

Generated by OpenCVE AI on April 28, 2026 at 10:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Listeo Core to version 2.0.19 or later.
  • If upgrade is not possible, mitigate by enforcing a strong Content‑Security‑Policy that disallows execution of inline scripts in pages generated by the plugin.
  • Disable or remove the Listeo Core plugin from sites that do not require it.

Generated by OpenCVE AI on April 28, 2026 at 10:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 09 Jan 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Purethemes
Purethemes listeo
Wordpress
Wordpress wordpress
Vendors & Products Purethemes
Purethemes listeo
Wordpress
Wordpress wordpress

Thu, 08 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Jan 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Thu, 08 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes Listeo Core listeo-core allows Reflected XSS.This issue affects Listeo Core: from n/a through < 2.0.19.
Title WordPress Listeo Core plugin < 2.0.19 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Purethemes Listeo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:23.618Z

Reserved: 2025-12-15T09:59:55.700Z

Link: CVE-2025-67932

cve-icon Vulnrichment

Updated: 2026-01-08T14:54:00.255Z

cve-icon NVD

Status : Deferred

Published: 2026-01-08T10:15:52.263

Modified: 2026-04-27T18:16:50.357

Link: CVE-2025-67932

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T10:15:28Z

Weaknesses