
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13153 is a Stored Cross-Site Scripting (XSS) vulnerability in the Logo Slider WordPress plugin affecting all versions before 4.9.0. The flaw allows authenticated users with the Contributor role or above to inject and store malicious JavaScript via unvalidated slider options in the dashboard. It was publicly disclosed on December 12, 2025, by researcher Alex Tselevich (nos3curity) and assigned a CVSS v3.1 base score of 6.1 (Medium) by CISA-ADP (WPScan).
The root cause is improper neutralization of user-supplied input (CWE-79) in the Logo Slider plugin's Carousel settings, specifically in color picker fields such as Nav Color, Nav Hover Color, Background Color, Border Color, Pagination Color, and Active Color. These fields accept arbitrary HTML/JavaScript input that is stored and later rendered in the WordPress dashboard without sanitization or escaping. An attacker with at least Contributor-level access can inject a payload such as " autofocus onfocus="alert(document.cookie) into any of these fields, which executes when an administrator views the slider configuration. A verified proof-of-concept is publicly available via WPScan (WPScan).
Successful exploitation allows a low-privileged authenticated attacker to execute arbitrary JavaScript in the context of an administrator's browser session when they view the affected dashboard page. This can lead to session cookie theft, credential harvesting, unauthorized administrative actions (such as creating rogue admin accounts or installing malicious plugins), and potential full site compromise. Confidentiality and integrity are both impacted, though availability is not directly affected (WPScan).
A verified proof-of-concept is publicly documented by WPScan, demonstrating exploitation requires only Contributor-level WordPress credentials — a relatively low bar on sites that allow open registration or have multiple contributors. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (WPScan).
" autofocus onfocus="alert(document.cookie). Other vulnerable fields include Nav Hover Color, Background Color, Background Hover Color, Border Color, Border Hover Color, Pagination Color, and Active Color.onfocus, autofocus, onerror) in color field parameters.wp_posts or plugin-specific option tables associated with Logo Slider slider configurations (e.g., fields containing <script>, onfocus=, alert().Update the Logo Slider WordPress plugin to version 4.9.0 or later, which includes proper validation and escaping of slider option fields. No configuration-based workaround is available; upgrading is the only effective remediation. Site administrators should also audit existing slider configurations for any suspicious values in color picker fields and review contributor-level user accounts for unauthorized access (WPScan).
The vulnerability was reported in the Wordfence Intelligence Weekly WordPress Vulnerability Report for December 8–14, 2025, which aggregates notable plugin vulnerabilities for the WordPress community. No significant vendor statements or broader media coverage beyond standard vulnerability tracking have been identified for this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."