
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13360 is a Cross-Site Request Forgery (CSRF) vulnerability in the Quantic Social Image Hover plugin for WordPress, affecting all versions up to and including 1.0.8. The flaw allows unauthenticated attackers to update plugin settings and inject malicious web scripts by tricking a site administrator into clicking a crafted link. It was published on December 5, 2025, and assigned by Wordfence. The CVSS v3.1 base score is 4.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is missing nonce validation on the plugin's settings update functionality (CWE-352: Cross-Site Request Forgery). Because the settings endpoint does not verify a WordPress nonce, an attacker can craft a forged HTTP request that, when triggered by an authenticated administrator, updates plugin settings and injects arbitrary JavaScript or HTML — effectively achieving stored XSS through the CSRF vector. Exploitation requires no privileges but does require user interaction (the administrator must click a malicious link or visit an attacker-controlled page). The vulnerable code is visible in the plugin's source at line 103 of tw-image-hover.php (Wordfence, WordPress Trac).
Successful exploitation allows an attacker to modify the Quantic Social Image Hover plugin's settings and inject malicious scripts into the WordPress site, resulting in stored XSS that affects all visitors of the compromised site. The primary impact is on integrity (script injection), with no direct confidentiality or availability impact per the CVSS assessment. Injected scripts could be used to steal session cookies, redirect users to phishing pages, or perform further attacks against site visitors (Wordfence).
tw-image-hover-share) at version 1.0.8 or earlier, using tools like WPScan or passive enumeration.<script> tag into a plugin setting field).admin-ajax.php or plugin-specific admin pages) from unusual referrers or external origins.wp_options table) containing <script> tags or encoded JavaScript payloads in Quantic Social Image Hover plugin options.Users should update the Quantic Social Image Hover plugin to version 1.0.9 or later, which includes proper nonce validation on the settings update functionality. As an interim workaround, administrators can deactivate and remove the plugin until the update can be applied. Restricting access to the WordPress admin panel via IP allowlisting can also reduce the attack surface (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."