VYPR
High severity7.1NVD Advisory· Published Apr 24, 2025· Updated Apr 23, 2026

CVE-2025-46478

CVE-2025-46478

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in metaloha Dropdown Content dropdown-content allows Stored XSS.This issue affects Dropdown Content: from n/a through <= 1.0.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in WordPress Dropdown Content plugin ≤1.0.2 allows attackers to inject malicious scripts into pages, executed for visitors.

The WordPress Dropdown Content plugin, versions 1.0.2 and earlier, contains a stored cross-site scripting (XSS) vulnerability arising from improper neutralization of user input during webpage generation [1]. This allows an authenticated attacker with sufficient privileges to inject arbitrary HTML and JavaScript code into the plugin's output, where it is stored on the server and subsequently rendered in the browsers of site visitors [1].

Exploitation requires the attacker to have a role capable of inserting or editing content that passes through the vulnerable plugin component, and a privileged user (such as an admin) may need to perform an action like visiting a crafted page or clicking a malicious link to store the payload [1]. Once stored, the injected script executes automatically when any user views the affected page, without further interaction from the victim [1].

The impact of successful exploitation includes the execution of arbitrary script code in the context of the target user's browser, which can be used to redirect visitors, display advertisements, steal session cookies, or deface the site [1]. The vulnerability carries a CVSS v3 base score of 7.1, indicating high severity [1].

Users are strongly advised to update the Dropdown Content plugin to a patched version as soon as possible [1]. If an update is not available, those unable to upgrade should seek assistance from their hosting provider or web developer to implement temporary mitigation measures [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.