CVE-2025-13153: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13153 is a Stored Cross-Site Scripting (XSS) vulnerability in the Logo Slider WordPress plugin affecting all versions before 4.9.0. The flaw allows authenticated users with the Contributor role or above to inject and store malicious JavaScript via unvalidated slider options in the dashboard. It was publicly disclosed on December 12, 2025, by researcher Alex Tselevich (nos3curity) and assigned a CVSS v3.1 base score of 6.1 (Medium) by CISA-ADP (WPScan).

Technical details

The root cause is improper neutralization of user-supplied input (CWE-79) in the Logo Slider plugin's Carousel settings, specifically in color picker fields such as Nav Color, Nav Hover Color, Background Color, Border Color, Pagination Color, and Active Color. These fields accept arbitrary HTML/JavaScript input that is stored and later rendered in the WordPress dashboard without sanitization or escaping. An attacker with at least Contributor-level access can inject a payload such as " autofocus onfocus="alert(document.cookie) into any of these fields, which executes when an administrator views the slider configuration. A verified proof-of-concept is publicly available via WPScan (WPScan).

Impact

Successful exploitation allows a low-privileged authenticated attacker to execute arbitrary JavaScript in the context of an administrator's browser session when they view the affected dashboard page. This can lead to session cookie theft, credential harvesting, unauthorized administrative actions (such as creating rogue admin accounts or installing malicious plugins), and potential full site compromise. Confidentiality and integrity are both impacted, though availability is not directly affected (WPScan).

Exploitability

A verified proof-of-concept is publicly documented by WPScan, demonstrating exploitation requires only Contributor-level WordPress credentials — a relatively low bar on sites that allow open registration or have multiple contributors. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (WPScan).

Exploitation steps

  1. Gain Contributor Access: Log in to the target WordPress site with a Contributor-level (or higher) account, which may be obtained via registration, phishing, or credential stuffing.
  2. Navigate to Logo Slider: In the WordPress admin dashboard, click the Logo Slider tab → Shortcode Generator → Add New Slider.
  3. Create a Slider: Enter any name (e.g., "Test") for the new slider and navigate to the Carousel tab → Navigation Settings.
  4. Inject XSS Payload: Click the Nav Color (or any other vulnerable color picker field) and paste the payload: " autofocus onfocus="alert(document.cookie). Other vulnerable fields include Nav Hover Color, Background Color, Background Hover Color, Border Color, Border Hover Color, Pagination Color, and Active Color.
  5. Submit the Slider: Click "Submit for Review" to save the slider with the stored payload.
  6. Trigger Execution: The injected JavaScript executes immediately upon saving, and will also execute whenever an administrator views the slider configuration in the dashboard, enabling session cookie theft or further malicious actions (WPScan).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to admin-ajax.php or slider configuration endpoints containing HTML event handler strings (e.g., onfocus, autofocus, onerror) in color field parameters.
  • Database: Unexpected JavaScript or HTML event handler strings stored in the wp_posts or plugin-specific option tables associated with Logo Slider slider configurations (e.g., fields containing <script>, onfocus=, alert().
  • Browser/Admin Session: Unexpected JavaScript alert dialogs or console errors appearing when administrators access the Logo Slider dashboard section.
  • Network: Outbound requests from administrator browsers to unknown external domains shortly after accessing the Logo Slider admin page, potentially indicating cookie exfiltration.

Mitigation and workarounds

Update the Logo Slider WordPress plugin to version 4.9.0 or later, which includes proper validation and escaping of slider option fields. No configuration-based workaround is available; upgrading is the only effective remediation. Site administrators should also audit existing slider configurations for any suspicious values in color picker fields and review contributor-level user accounts for unauthorized access (WPScan).

Community reactions

The vulnerability was reported in the Wordfence Intelligence Weekly WordPress Vulnerability Report for December 8–14, 2025, which aggregates notable plugin vulnerabilities for the WordPress community. No significant vendor statements or broader media coverage beyond standard vulnerability tracking have been identified for this CVE.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management