Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WC Builder wc-builder allows Stored XSS.This issue affects WC Builder: from n/a through <= 1.2.0.
Published: 2025-12-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of user input during web page generation in the HasThemes WC Builder plugin. When attackers submit input through the plugin’s fields, malicious script payloads can be stored and later rendered in the browsers of visitors to the site. This allows the injection and execution of arbitrary client‑side code.

Affected Systems

All installations of the WC Builder plugin from HasThemes that are version 1.2.0 or earlier are affected. Any WordPress site that has this plugin deployed and has not upgraded beyond that version may be vulnerable.

Risk and Exploitability

The CVSS score of 6.5 categorizes the issue as medium severity, and the EPSS score of less than 1% indicates a low probability of exploitation at this time. It is not listed in the CISA KEV catalog. Based on the description, the attacker likely needs access to the WordPress administrative interface or other user roles that can submit data to the plugin in order to inject the malicious payload.

Generated by OpenCVE AI on April 29, 2026 at 18:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WC Builder plugin to a version newer than 1.2.0.
  • Restrict access to the plugin’s input fields so that only trusted administrators can submit data.
  • Deploy a web application firewall or enable a strict Content Security Policy to block injected scripts.

Generated by OpenCVE AI on April 29, 2026 at 18:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Thu, 29 Jan 2026 16:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:hasthemes:wc_builder:*:*:*:*:*:wordpress:*:*

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Hasthemes
Hasthemes wc Builder
Wordpress
Wordpress wordpress
Vendors & Products Hasthemes
Hasthemes wc Builder
Wordpress
Wordpress wordpress

Wed, 24 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 12:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WC Builder wc-builder allows Stored XSS.This issue affects WC Builder: from n/a through <= 1.2.0.
Title WordPress WC Builder plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Hasthemes Wc Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:29.524Z

Reserved: 2025-12-19T10:17:03.706Z

Link: CVE-2025-68533

cve-icon Vulnrichment

Updated: 2025-12-24T19:06:53.519Z

cve-icon NVD

Status : Modified

Published: 2025-12-24T13:16:22.727

Modified: 2026-04-27T19:16:28.780

Link: CVE-2025-68533

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T18:45:17Z

Weaknesses