Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xenioushk BWL Pro Voting Manager bwl-pro-voting-manager allows DOM-Based XSS.This issue affects BWL Pro Voting Manager: from n/a through <= 1.4.9.
Published: 2025-12-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper neutralization of user input in the BWL Pro Voting Manager plugin, allowing malicious scripts to be injected into the page via DOM manipulation. An attacker can inject client‑side code that runs in the victim’s browser, potentially stealing session cookies, defacing the site, or redirecting users to phishing pages. Because the flaw is limited to the browser, the impact is confined to the victim’s session and data, but privileged users who view or manage the votes could be targeted for credential theft.

Affected Systems

The issue affects the WordPress BWL Pro Voting Manager plugin by xenioushk, specifically all releases up to and including version 1.4.9. Users running any of those plugin versions on a WordPress site are potentially vulnerable and should check the installed version or update the plugin.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% suggests uncommon exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that an attacker can cause a user to load a page containing the malicious input—commonly by crafting a URL or embedding the payload in a voting form that an authenticated or unauthenticated user will access. Attackers can thus compromise user sessions through the victim’s browser when the vulnerable plugin is present.

Generated by OpenCVE AI on April 29, 2026 at 18:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the BWL Pro Voting Manager plugin to a version newer than 1.4.9, which contains the XSS fix.
  • If an immediate upgrade is not possible, configure the site to restrict voting functionality to trusted administrators only, preventing public users from submitting potentially malicious input.
  • Implement a strong Content‑Security‑Policy that blocks inline scripts, mitigating the impact of any remaining DOM‑based XSS attempts.

Generated by OpenCVE AI on April 29, 2026 at 18:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 30 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xenioushk BWL Pro Voting Manager bwl-pro-voting-manager allows DOM-Based XSS.This issue affects BWL Pro Voting Manager: from n/a through <= 1.4.9.
Title WordPress BWL Pro Voting Manager plugin <= 1.4.9 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:33.772Z

Reserved: 2025-12-29T11:18:04.294Z

Link: CVE-2025-68991

cve-icon Vulnrichment

Updated: 2025-12-30T19:43:11.729Z

cve-icon NVD

Status : Deferred

Published: 2025-12-30T11:15:57.803

Modified: 2026-04-27T19:16:40.320

Link: CVE-2025-68991

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T18:30:17Z

Weaknesses