CVE-2025-14130: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14130 is a Reflected Cross-Site Scripting (XSS) vulnerability in the Post Like Dislike plugin for WordPress, affecting all versions up to and including 1.0. The flaw stems from insufficient input sanitization and output escaping of the $_SERVER['PHP_SELF'] variable. It was assigned by Wordfence and published on January 7, 2026. The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium) (Wordfence).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). The plugin directly reflects the PHP server variable $_SERVER['PHP_SELF'] into page output without sanitization or escaping, which is a well-known PHP anti-pattern. An unauthenticated attacker can craft a malicious URL containing injected JavaScript that, when visited by a victim, causes the script to execute in the victim's browser context. The vulnerable code is visible at line 106 of the plugin source (WordPress Plugin Trac, Wordfence).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of a victim who clicks a crafted link, with a changed scope affecting the victim's session rather than the server directly. This can lead to session token theft, credential harvesting, phishing overlays, or redirection to malicious sites. Confidentiality and integrity impacts are rated Low, and there is no direct availability impact (Wordfence).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-14130. The EPSS score is approximately 0.061%, indicating a low probability of exploitation in the near term. The vulnerability requires user interaction (victim clicking a malicious link), which reduces practical exploitability. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Post Like Dislike plugin version 1.0 or earlier, using tools like WPScan or by checking publicly accessible plugin metadata.
  2. Craft malicious URL: Construct a URL targeting a page that uses the plugin, appending a crafted path segment or query string that injects a JavaScript payload via the PHP_SELF variable (e.g., https://victim-site.com/wp-page/%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E).
  3. Deliver the link: Send the crafted URL to a target user via phishing email, social media, or other social engineering channels.
  4. Payload execution: When the victim clicks the link and loads the page, the unsanitized $_SERVER['PHP_SELF'] value is reflected into the HTML output, causing the injected script to execute in the victim's browser, potentially stealing session cookies or performing actions on behalf of the user (Wordfence, WordPress Plugin Trac).

Indicators of compromise

  • Network: HTTP requests to WordPress pages using the Post Like Dislike plugin containing URL-encoded script tags or JavaScript event handlers in the path component (e.g., %3Cscript%3E, %22%3E, onerror=).
  • Logs: Web server access logs showing unusual characters or encoded payloads in the request URI path on pages where the plugin is active.
  • Browser/Client-Side: Unexpected JavaScript execution, session cookie exfiltration attempts, or redirects to external domains originating from plugin-rendered pages.

Mitigation and workarounds

The Post Like Dislike plugin version 1.0 is the only known release and remains vulnerable; no patched version has been published as of the disclosure date. Site administrators should deactivate and remove the plugin until a fixed version is available. As a general mitigation, deploying a Web Application Firewall (WAF) — such as Wordfence — can help block reflected XSS payloads targeting this and similar vulnerabilities (Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management