CVE-2025-46478
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in metaloha Dropdown Content dropdown-content allows Stored XSS.This issue affects Dropdown Content: from n/a through <= 1.0.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in WordPress Dropdown Content plugin ≤1.0.2 allows attackers to inject malicious scripts into pages, executed for visitors.
The WordPress Dropdown Content plugin, versions 1.0.2 and earlier, contains a stored cross-site scripting (XSS) vulnerability arising from improper neutralization of user input during webpage generation [1]. This allows an authenticated attacker with sufficient privileges to inject arbitrary HTML and JavaScript code into the plugin's output, where it is stored on the server and subsequently rendered in the browsers of site visitors [1].
Exploitation requires the attacker to have a role capable of inserting or editing content that passes through the vulnerable plugin component, and a privileged user (such as an admin) may need to perform an action like visiting a crafted page or clicking a malicious link to store the payload [1]. Once stored, the injected script executes automatically when any user views the affected page, without further interaction from the victim [1].
The impact of successful exploitation includes the execution of arbitrary script code in the context of the target user's browser, which can be used to redirect visitors, display advertisements, steal session cookies, or deface the site [1]. The vulnerability carries a CVSS v3 base score of 7.1, indicating high severity [1].
Users are strongly advised to update the Dropdown Content plugin to a patched version as soon as possible [1]. If an update is not available, those unable to upgrade should seek assistance from their hosting provider or web developer to implement temporary mitigation measures [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <= 1.0.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.