Cyber Posture

CVE-2025-1486

HighPublic PoC

Published: 13 March 2025

Published
13 March 2025
Modified
09 April 2025
KEV Added
Patch
CVSS Score 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EPSS Score 0.0009 25.0th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may abuse various implementations of JavaScript for execution.

Security Summary

CVE-2025-2025-1486, published on 2025-03-13, is a reflected cross-site scripting (XSS) vulnerability in the WoWPth WordPress plugin through version 2.0. The plugin fails to sanitize and escape a parameter before outputting it back in the page, enabling attackers to inject malicious scripts. It carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L) and maps to CWE-79 (Improper Neutralization of Input During Web Page Generation).

An unauthenticated attacker can exploit this over the network with low complexity by tricking a high-privilege user, such as an administrator, into interacting with a malicious link or page (UI:R). Upon success, arbitrary JavaScript executes in the victim's browser context with changed scope (S:C), potentially leading to low-level impacts on confidentiality, integrity, and availability, such as session hijacking or unauthorized actions as the targeted user.

The WPScan advisory at https://wpscan.com/vulnerability/182ecda8-3385-4f9f-a917-efdeb237247c/ provides additional details on this vulnerability, including potential mitigation steps.

Details

CWE(s)
CWE-79

Affected Products

andreafarracani
wowpth
≤ 2.0

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1059.007 JavaScript Execution
Adversaries may abuse various implementations of JavaScript for execution.
Why these techniques?

Reflected XSS in public-facing WordPress plugin enables exploitation of public-facing applications (T1190) and execution of arbitrary JavaScript via malicious link (T1059.007).

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References