Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Filter blog-filter allows DOM-Based XSS.This issue affects Blog Filter: from n/a through <= 1.7.3.
Published: 2025-12-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a DOM-based Cross- Site Scripting flaw that occurs when the A WP Life Blog Filter plugin fails to neutralize user input during web page rendering. An attacker can supply a crafted URL or otherwise manipulate a page element so that malicious script code runs in the browser of any visitor. Such script execution could lead to session hijacking, credential theft, defacement, or the execution of further attacks within the victim’s browser context. The weakness is a classic input-validation issue classified as CWE-79.

Affected Systems

The flaw affects the A WP Life Blog Filter plugin for WordPress versions through and including 1.7.3. All earlier releases are also vulnerable. The product is listed as "A WP Life:Blog Filter" in the CNA data.

Risk and Exploitability

With a CVSS score of 6.5 the severity is moderate; the EPSS score of less than 1% indicates a very low but nonzero likelihood of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalogue. It is a DOM-based XSS, so the attack vector is typically browser-based and would require a victim to visit a crafted URL or view a page with malicious content served by the affected plugin. Given the moderate severity and low EPSS, the risk to organizations is manageable but not negligible, especially for sites where the plugin is exposed to untrusted users or content. Threat actors with low resources might still target high-traffic sites to use the XSS payload for phishing or token theft.

Generated by OpenCVE AI on April 29, 2026 at 12:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Blog Filter plugin to the latest available release that resolves the XSS flaw
  • If the plugin cannot be upgraded immediately, deactivate it until a patched version is available
  • Configure a strict Content Security Policy that disallows inline scripts and restricts script sources to trusted domains

Generated by OpenCVE AI on April 29, 2026 at 12:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Awplife
Awplife blog Filter
Wordpress
Wordpress wordpress
Vendors & Products Awplife
Awplife blog Filter
Wordpress
Wordpress wordpress

Tue, 30 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Filter blog-filter allows DOM-Based XSS.This issue affects Blog Filter: from n/a through <= 1.7.3.
Title WordPress Blog Filter plugin <= 1.7.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Awplife Blog Filter
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:34:06.260Z

Reserved: 2025-12-29T11:18:35.618Z

Link: CVE-2025-69033

cve-icon Vulnrichment

Updated: 2026-01-05T13:00:48.531Z

cve-icon NVD

Status : Deferred

Published: 2025-12-30T11:16:01.940

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-69033

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T12:15:09Z

Weaknesses