Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shoutoutglobal ShoutOut shoutout allows Reflected XSS.This issue affects ShoutOut: from n/a through <= 4.0.2.
Published: 2026-01-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ShoutOut plugin fails to neutralize user input that is reflected in the HTML output, enabling a reflected XSS vulnerability (CWE‑79). An attacker can embed malicious script in the URL or form input that the plugin echoes back in the page, causing the victim's browser to execute arbitrary JavaScript in the context of the site. This can lead to theft of session cookies, credential hijacking, defacement, or redirecting the user to a phishing page. The impact is limited to the victim's browser and does not directly affect the server, but it can compromise user data or influence client‑side behaviour. The likely attack vector is a maliciously crafted URL or form input that includes unsafe script content, which the plugin reflects back unchanged.

Affected Systems

This vulnerability affects the WordPress ShoutOut plugin provided by ShoutOut global. All instances of the plugin with version 4.0.2 or earlier are vulnerable. No specific patch versions are listed in the CVE text, but the enterprise should upgrade beyond 4.0.2.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, reflecting the ease of exploitation and the potential impact on affected users. The EPSS score is below 1%, suggesting that, while the vulnerability exists, the probability of active exploitation at the time of this analysis is low. The vulnerability is not currently listed in CISA's KEV catalog, so there is no evidence of widespread exploitation. The likely attack vector is forcing a victim to visit a specially crafted URL or input field that contains malicious code, typically via email or social engineering. Attackers would drive a victim to a specially crafted URL or input field to trigger the reflected XSS, typically via email or social engineering. The exploit conditions are minimal: the site must have the plugin installed and the victim must visit the crafted link while authenticated or having a session cookie associated with the site. Given the lack of server‑side consequences, the primary risk is to end users rather than to system integrity.

Generated by OpenCVE AI on April 29, 2026 at 11:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the ShoutOut plugin to a version newer than 4.0.2 (ideally 4.0.3 or later).
  • If an upgrade is not available, disable or uninstall the ShoutOut plugin to prevent reflective input rendering.
  • As a temporary measure, configure the site’s Content Security Policy to block inline scripts and enable XSS filtering in the browser to mitigate potential execution of reflected scripts.

Generated by OpenCVE AI on April 29, 2026 at 11:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 27 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shoutoutglobal ShoutOut shoutout allows Reflected XSS.This issue affects ShoutOut: from n/a through <= 4.0.2.
Title WordPress ShoutOut plugin <= 4.0.2 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:07:04.757Z

Reserved: 2025-12-24T14:00:47.908Z

Link: CVE-2025-68894

cve-icon Vulnrichment

Updated: 2026-01-27T21:25:41.329Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:13.040

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-68894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T12:00:11Z

Weaknesses