VYPR
Medium severity6.5NVD Advisory· Published Apr 24, 2025· Updated Apr 23, 2026

CVE-2025-46438

CVE-2025-46438

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in warmwhisky GTDB Guitar Tuners guitar-tuner allows Stored XSS.This issue affects GTDB Guitar Tuners: from n/a through <= 4.2.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS vulnerability in GTDB Guitar Tuners WordPress plugin allows authenticated attackers with contributor-level access to inject malicious scripts, affecting versions up to 4.2.2.

The GTDB Guitar Tuners plugin for WordPress (versions through 4.2.2) contains a stored cross-site scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation [1]. This allows an attacker to inject arbitrary JavaScript or HTML that is stored on the server and later executed in the browsers of visitors.

Exploitation requires an authenticated user with at least contributor-level privileges to submit crafted input through a plugin feature, such as tuner settings or custom content fields [1]. While user interaction (e.g., clicking a link) is needed to trigger the initial injection, the stored payload then executes automatically for any subsequent visitor viewing the affected page.

Successful exploitation enables an attacker to inject malicious scripts that can perform actions like redirecting users to phishing sites, displaying unwanted advertisements, or stealing session cookies [1]. The advisory notes that this type of vulnerability is frequently used in mass-exploit campaigns targeting thousands of WordPress sites.

As a mitigation, users should immediately update the plugin to a version newer than 4.2.2. If updating is not possible, the advisory recommends contacting a hosting provider or web developer for assistance [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.