CVE-2025-28988
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aharonyan WP Front User Submit / Front Editor front-editor allows Reflected XSS.This issue affects WP Front User Submit / Front Editor: from n/a through <= 4.9.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reflected XSS vulnerability in WP Front User Submit / Front Editor plugin for WordPress allows attackers to inject malicious scripts via crafted requests.
The WP Front User Submit / Front Editor plugin for WordPress versions up to and including 4.9.3 contains a reflected cross-site scripting (XSS) vulnerability due to improper neutralization of user input during web page generation [1]. This flaw allows an attacker to inject arbitrary HTML and JavaScript into a page, which is then executed in the browser of a victim who visits a specially crafted URL.
Exploitation requires user interaction, such as clicking a malicious link or visiting a crafted page [1]. The attacker does not need authentication to deliver the payload, but the victim must be a privileged user (e.g., an administrator) for the script to execute in a sensitive context. This makes the vulnerability suitable for mass-exploit campaigns targeting WordPress sites regardless of size or popularity [1].
Successful exploitation could allow an attacker to perform actions like redirecting visitors to malicious sites, injecting advertisements, or stealing session cookies [1]. The CVSS score of 7.1 (High) reflects the potential for significant impact with relatively low complexity.
The vulnerability is patched in version 4.9.4 of the plugin [1]. Users are strongly advised to update immediately. For those unable to update, Patchstack offers a mitigation rule to block attacks until the update is applied [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.