Description
The Auto Bulb Finder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'abf_vehicle' shortcode in all versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2025-10-03
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Patch
AI Analysis

Impact

The Auto Bulb Finder for WordPress plugin is vulnerable to stored Cross‑Site Scripting through its "abf_vehicle" shortcode. Improper input sanitization and lack of output escaping allow attackers to embed JavaScript in the attributes supplied by authenticated users. The injected scripts run whenever a page containing the shortcode is viewed, potentially giving the attacker the ability to steal session cookies, deface content, or execute further malicious actions within the victim’s browser context. Based solely on the supplied description, the vulnerability does not grant arbitrary code execution on the server but empowers client‑side script execution that can affect any user that views the compromised page. The noted only user role required is contributor or higher, indicating the vector is limited to authenticated accounts with moderate permissions.

Affected Systems

This flaw affects the mtoolstec Auto Bulb Finder for WordPress plugin, versions up to and including 2.8.0. Any WordPress site that has this plugin installed and permits contributor‑level or higher user accounts to insert the "abf_vehicle" shortcode is susceptible. The issue is confined to the plugin and does not extend to core WordPress components or other plugins.

Risk and Exploitability

The CVSS score of 6.4 classifies the vulnerability as moderate, and the EPSS score of less than 1% indicates a low probability of being exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access with contributor privileges; an attacker would need to supply a crafted shortcode containing malicious JavaScript that is then stored by the plugin and executed for any site visitor. While the attack requires user authentication, once in place it can impact all users who view the affected page, providing broad exposure for client‑side attacks.

Generated by OpenCVE AI on April 20, 2026 at 19:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest version of the Auto Bulb Finder plugin (v2.9 or newer).
  • If an update is unavailable, modify the plugin’s shortcode handler to escape or validate the "abf_vehicle" attributes before rendering them.
  • If the plugin cannot be updated or patched, remove the "abf_vehicle" shortcode from the site or disable the plugin entirely.

Generated by OpenCVE AI on April 20, 2026 at 19:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-32254 The Auto Bulb Finder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'abf_vehicle' shortcode in all versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
History

Wed, 08 Apr 2026 18:30:00 +0000


Mon, 06 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Mtoolstec
Mtoolstec auto Bulb Finder
Wordpress
Wordpress wordpress
Vendors & Products Mtoolstec
Mtoolstec auto Bulb Finder
Wordpress
Wordpress wordpress

Fri, 03 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Oct 2025 11:30:00 +0000

Type Values Removed Values Added
Description The Auto Bulb Finder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'abf_vehicle' shortcode in all versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Auto Bulb Finder for WordPress <= 2.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Mtoolstec Auto Bulb Finder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:19:51.218Z

Reserved: 2025-09-02T15:41:32.143Z

Link: CVE-2025-9858

cve-icon Vulnrichment

Updated: 2025-10-03T13:59:26.173Z

cve-icon NVD

Status : Deferred

Published: 2025-10-03T12:15:49.093

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-9858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T19:30:06Z

Weaknesses