
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12520 is a Stored Cross-Site Scripting (XSS) vulnerability in the WP Airbnb Review Slider plugin for WordPress, affecting all versions up to and including 4.2. The flaw stems from insufficient URL validation in admin settings, allowing authenticated administrators to pull in a malicious HTML file and inject arbitrary web scripts into pages. It was published on November 7, 2025, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 4.0 (Medium), and is limited to multi-site WordPress installations or those where unfiltered_html has been disabled (Wordfence, Red Hat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The plugin fails to adequately validate URLs supplied through admin settings, allowing an attacker to reference an externally hosted malicious HTML file that is subsequently rendered in the context of the WordPress site. Exploitation requires network access, high attack complexity, administrator-level authentication, and user interaction (a victim must visit the injected page), and is only possible in multi-site environments or where unfiltered_html is disabled. A patch diff is publicly available via the WordPress plugin repository changeset (WordPress Trac).
Successful exploitation allows an authenticated administrator to persistently inject malicious JavaScript into WordPress pages, which executes in the browsers of any user who visits the affected page. The primary impacts are limited confidentiality loss (e.g., session token theft) and integrity loss (e.g., page content manipulation), with no direct availability impact. Due to the high privilege requirement and constrained deployment conditions, the practical blast radius is narrow, but in multi-site environments a compromised super-admin could affect multiple sub-sites (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-12520. The EPSS score is approximately 0.021% (0.000210), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The high privilege requirement (administrator-level) and additional preconditions (multi-site or unfiltered_html disabled) significantly limit the exploitability of this flaw (Feedly).
unfiltered_html disabled that uses the WP Airbnb Review Slider plugin version ≤ 4.2.Users should update the WP Airbnb Review Slider plugin to version 4.3 or later, which addresses the insufficient URL validation. The patch is available via the official WordPress plugin repository. As a temporary workaround where immediate patching is not possible, administrators can disable the plugin or restrict access to the plugin's settings page. Ensuring unfiltered_html remains enabled (where appropriate) also removes one of the preconditions for exploitation (WordPress Trac, Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."