Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Popping Sidebars and Widgets Light popping-sidebars-and-widgets-light allows Stored XSS.This issue affects Popping Sidebars and Widgets Light: from n/a through <= 1.27.
Published: 2025-12-30
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability creates an improper neutralization of input during web page generation that allows stored cross‑site scripting through the OTWthemes Popping Sidebars and Widgets Light plugin. An attacker who can inject content via the plugin’s administrative interface can embed malicious scripts that execute in the browsers of any site visitor, potentially enabling session hijacking, credential theft, defacement, or the execution of arbitrary client‑side actions. The weakness is categorized as CWE‑79. The impact is confined to affected WordPress sites that use the vulnerable plugin, but the effects can extend to all site users who view the compromised content.

Affected Systems

WordPress sites using OTWthemes Popping Sidebars and Widgets Light plugin with versions from the lowest available up to and including 1.27 are affected. Upgrading or removing the plugin eliminates the vulnerability.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the near term. The CVE does not state the required attacker level, but it is inferred that an attacker would need some level of control over the plugin’s administrative interface to inject malicious payloads that are stored and rendered. Once stored, the bad script runs in the browsers of all users who view the affected content. The vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on April 29, 2026 at 12:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a plugin update to version 1.28 or later, which contains the fix for the stored XSS flaw.
  • If an update is not immediately possible, delete the Popping Sidebars and Widgets Light plugin to remove the attack surface.
  • As a temporary measure, disable any widget or sidebar features that accept user‑supplied content until a patch is applied.

Generated by OpenCVE AI on April 29, 2026 at 12:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Otwthemes
Otwthemes popping Sidebars And Widgets Light
Wordpress
Wordpress wordpress
Vendors & Products Otwthemes
Otwthemes popping Sidebars And Widgets Light
Wordpress
Wordpress wordpress

Tue, 30 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Popping Sidebars and Widgets Light popping-sidebars-and-widgets-light allows Stored XSS.This issue affects Popping Sidebars and Widgets Light: from n/a through <= 1.27.
Title WordPress Popping Sidebars and Widgets Light plugin <= 1.27 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Otwthemes Popping Sidebars And Widgets Light
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:32:11.261Z

Reserved: 2025-12-29T11:18:21.372Z

Link: CVE-2025-69007

cve-icon Vulnrichment

Updated: 2025-12-30T14:44:40.306Z

cve-icon NVD

Status : Deferred

Published: 2025-12-30T11:15:58.930

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-69007

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T12:15:09Z

Weaknesses