Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in councilsoft Content Grid Slider content-grid-slider allows Reflected XSS.This issue affects Content Grid Slider: from n/a through <= 1.5.
Published: 2025-12-29
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Content Grid Slider plugin contains an Improper Neutralization of Input during web page generation, resulting in a reflected cross‑site scripting vulnerability. An attacker can embed malicious scripts into a URL that, when accessed by a user, execute in the victim’s browser with the same privileges as the user. This can lead to session hijacking, data theft, defacement or the initiation of further attacks against the site or its visitors. The weakness is catalogued as CWE‑79 and does not allow remote code execution beyond the browser sandbox, but it has significant confidentiality and integrity implications for any user who clicks a crafted link.

Affected Systems

The vulnerability affects the councilsoft Content Grid Slider WordPress plugin. All installed versions from an unspecified earliest release up to and including version 1.5 are vulnerable. Users running any of these versions should check and update the plugin.

Risk and Exploitability

The CVSS score of 7.1 reflects a moderate‑high severity, while the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread or confirmed exploitation yet. The most likely attack vector is a web‑based one: an attacker creates a malicious URL and persuades a victim to click it or injects it into a page that the victim will visit. If the victim’s browser executes the script, the attacker can perform actions that appear to come from the victim.

Generated by OpenCVE AI on April 29, 2026 at 15:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Content Grid Slider plugin to the latest available version (>= 1.6) which removes the reflected XSS flaw.
  • If an upgrade is temporarily infeasible, modify the plugin’s code to apply proper escaping (e.g., use WordPress esc_html() or esc_attr()) on any user‑controlled output that is currently rendered without sanitization.
  • Deploy a web‑application firewall rule or use a security plugin that blocks or logs attempts to execute suspicious JavaScript payloads targeting the plugin’s input fields.

Generated by OpenCVE AI on April 29, 2026 at 15:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Councilsoft Content Grid Slider allows Reflected XSS.This issue affects Content Grid Slider: from n/a through 1.5. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in councilsoft Content Grid Slider content-grid-slider allows Reflected XSS.This issue affects Content Grid Slider: from n/a through <= 1.5.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Mon, 29 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Councilsoft Content Grid Slider allows Reflected XSS.This issue affects Content Grid Slider: from n/a through 1.5.
Title WordPress Content Grid Slider plugin <= 1.5 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:32.164Z

Reserved: 2025-12-24T14:00:32.363Z

Link: CVE-2025-68879

cve-icon Vulnrichment

Updated: 2025-12-29T16:48:30.892Z

cve-icon NVD

Status : Deferred

Published: 2025-12-29T16:15:43.160

Modified: 2026-04-23T15:36:11.190

Link: CVE-2025-68879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T15:15:14Z

Weaknesses