Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Netrr Author Box WP Lens author-box-for-divi allows Stored XSS.This issue affects Author Box WP Lens: from n/a through <= 2.1.5.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Author Box WP Lens plugin (by Netrr) suffers from a stored cross‑site scripting flaw due to improper input neutralization. It is inferred that the attacker can inject malicious JavaScript into an author box field, which the plugin stores without sanitization and later renders in the page. This permits the execution of arbitrary scripts in the browsers of any visitor, potentially cookie theft, defacement, or malicious redirects. The weakness is identified as CWE‑79.

Affected Systems

WordPress sites running Netrr’s Author Box WP Lens plugin version 2.1.5 or earlier are vulnerable. The issue applies across all releases from the initial release up to and including 2.1.5. Site administrators should verify the plugin version and upgrade or disable the plugin accordingly.

Risk and Exploitability

The CVSS base score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of active exploitation. It is inferred that the attack vector is purely web‑based, requiring only that an authenticated user input malicious code into the plugin’s author box interface. Because the code is stored and served to all visitors, exploitation does not require elevated privileges after the initial injection but can impact all users of the site. It is also inferred that the plugin’s widespread use on WordPress sites increases the potential impact. Currently, the vulnerability is not listed in CISA’s KEV catalog, so there is no known large‑scale exploitation, but the potential for misuse remains high.

Generated by OpenCVE AI on July 31, 2026 at 11:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Author Box WP Lens plugin to version 2.1.6 or later from the official repository.
  • If an upgrade is not yet possible, deactivate the plugin or remove the author box display from the site until the fixed version is available.
  • Review and sanitize any custom author box content to ensure that user‑supplied data is properly escaped before rendering.

Generated by OpenCVE AI on July 31, 2026 at 11:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Netrr
Netrr author Box Wp Lens
Wordpress
Wordpress wordpress
Vendors & Products Netrr
Netrr author Box Wp Lens
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Netrr Author Box WP Lens author-box-for-divi allows Stored XSS.This issue affects Author Box WP Lens: from n/a through <= 2.1.5.
Title WordPress Author Box WP Lens plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Netrr Author Box Wp Lens
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:51.929Z

Reserved: 2026-06-24T12:46:38.624Z

Link: CVE-2026-57420

cve-icon Vulnrichment

Updated: 2026-07-13T16:02:17.744Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')