
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13728 is a Stored Cross-Site Scripting (XSS) vulnerability in the FluentAuth – The Ultimate Authorization & Security Plugin for WordPress. It affects all versions up to and including 2.0.3, where insufficient input sanitization and output escaping on user-supplied attributes in the fluent_auth_reset_password shortcode allow authenticated attackers with contributor-level access or above to inject arbitrary web scripts. The vulnerability was published on December 15, 2025, and assigned a CVSS v3.1 base score of 6.4 (Medium) by Wordfence (Wordfence, Red Hat CVE).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically due to insufficient input sanitization and output escaping on user-supplied attributes passed to the fluent_auth_reset_password shortcode in the plugin's CustomAuthHandler.php (Wordfence). An authenticated attacker with at least contributor-level WordPress access can embed a malicious shortcode containing arbitrary JavaScript into a page or post. When any user visits the affected page, the injected script executes in their browser context. The fix was introduced in version 2.1.0, as reflected in the plugin's changeset for CustomAuthHandler.php (WordPress Trac).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of users who visit pages containing the injected shortcode, affecting confidentiality and integrity. This can lead to session cookie theft, credential harvesting, account takeover of higher-privileged users (including administrators), and defacement of site content. The changed scope (S:C) in the CVSS vector indicates the impact extends beyond the plugin itself to the broader WordPress site and its users (Wordfence).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-13728. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access at the contributor level or above, which limits the attack surface compared to unauthenticated vulnerabilities.
fluent_auth_reset_password shortcode with a crafted attribute containing a malicious JavaScript payload, for example: [fluent_auth_reset_password attribute="\">"].wp-admin/post.php or REST API endpoints from contributor-level accounts containing shortcode content with unusual attribute values or encoded JavaScript.wp_posts table entries containing the fluent_auth_reset_password shortcode with unexpected or encoded attribute values (e.g., <script>, javascript:, onerror=, or base64-encoded strings).document.cookie).CustomAuthHandler.php or other plugin files if an attacker escalated to file write access after initial XSS exploitation.Site administrators should update the FluentAuth plugin to version 2.1.0 or later, which addresses the insufficient sanitization in CustomAuthHandler.php (WordPress Trac). As an interim measure, restrict contributor-level user registrations and limit the ability of untrusted users to publish or edit pages containing shortcodes. A Web Application Firewall (WAF) with XSS filtering rules can also help detect and block exploitation attempts while patching is pending (Wordfence).
Wordfence, the CNA that assigned and disclosed this CVE, included it in their weekly WordPress vulnerability report covering December 15, 2025 to January 4, 2026 (Wordfence Blog). The vulnerability received standard coverage from vulnerability aggregators such as VulDB, Vulners, and CVEFeed, with no notable broader media coverage or significant social media discussion observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."