CVE-2025-46438
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in warmwhisky GTDB Guitar Tuners guitar-tuner allows Stored XSS.This issue affects GTDB Guitar Tuners: from n/a through <= 4.2.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS vulnerability in GTDB Guitar Tuners WordPress plugin allows authenticated attackers with contributor-level access to inject malicious scripts, affecting versions up to 4.2.2.
The GTDB Guitar Tuners plugin for WordPress (versions through 4.2.2) contains a stored cross-site scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation [1]. This allows an attacker to inject arbitrary JavaScript or HTML that is stored on the server and later executed in the browsers of visitors.
Exploitation requires an authenticated user with at least contributor-level privileges to submit crafted input through a plugin feature, such as tuner settings or custom content fields [1]. While user interaction (e.g., clicking a link) is needed to trigger the initial injection, the stored payload then executes automatically for any subsequent visitor viewing the affected page.
Successful exploitation enables an attacker to inject malicious scripts that can perform actions like redirecting users to phishing sites, displaying unwanted advertisements, or stealing session cookies [1]. The advisory notes that this type of vulnerability is frequently used in mass-exploit campaigns targeting thousands of WordPress sites.
As a mitigation, users should immediately update the plugin to a version newer than 4.2.2. If updating is not possible, the advisory recommends contacting a hosting provider or web developer for assistance [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=4.2.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.