
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13527 is a Cross-Site Request Forgery (CSRF) vulnerability in the xShare plugin for WordPress, affecting all versions up to and including 1.0.1. The flaw allows unauthenticated attackers to reset the plugin's settings by tricking a site administrator into clicking a malicious link. It was published on January 7, 2026, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence).
The root cause is missing nonce validation on the xshare_plugin_reset() function within the xShare WordPress plugin (CWE-352: Cross-Site Request Forgery). Because the function does not verify a WordPress nonce before processing the reset action, an attacker can craft a forged HTTP request that, when triggered by an authenticated administrator, causes the plugin's settings to be reset without the administrator's intent. Exploitation requires social engineering — the attacker must trick a logged-in site administrator into visiting a malicious page or clicking a crafted link. The vulnerable code is visible in the plugin's source at line 50 of index.php (Wordfence, WordPress Plugin Trac).
Successful exploitation allows an unauthenticated attacker to reset the xShare plugin's configuration to its default state, affecting site integrity. The impact is limited to integrity loss (CVSS integrity impact: Low) with no confidentiality or availability impact. While not directly enabling remote code execution or data theft, resetting plugin settings could disrupt intended sharing functionality or expose the site to secondary misconfigurations (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-13527. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction (an administrator must be tricked into triggering the forged request), which further limits practical exploitability (Wordfence).
xshare_plugin_reset() (e.g., wp-admin/admin-post.php or equivalent action hook).xshare_plugin_reset() to execute and reset the plugin's settings without nonce verification (Wordfence).xshare_plugin_reset) from unusual referrer URLs or external origins.WordPress site administrators should update the xShare plugin to version 1.0.2 or later, which addresses the missing nonce validation in the xshare_plugin_reset() function. Until patching is possible, administrators should exercise caution when clicking links from untrusted sources while logged into the WordPress admin panel. General WordPress hardening practices — such as limiting admin account exposure and using security plugins that block CSRF attempts — can reduce risk (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."