
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49898 is a DOM-Based Cross-Site Scripting (XSS) vulnerability in the Xolluteon Dropshix WordPress plugin, affecting all versions through 4.0.14. The vulnerability was discovered by researcher Vinit Lakra, reported on June 26, 2025, and publicly disclosed on August 15, 2025. It carries a CVSS v3.1 base score of 5.9 (Medium) (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically manifesting as DOM-Based XSS. Exploitation requires an attacker with Administrator or Developer-level privileges to craft a malicious payload that is processed and rendered in the victim's browser DOM without proper sanitization. Because the attack is DOM-based, the malicious script executes client-side when a privileged user interacts with a crafted page or link, bypassing server-side filtering. No public proof-of-concept code has been identified at this time (Patchstack).
Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the context of a victim's browser session, potentially enabling session hijacking, credential theft, malicious redirects, or defacement of the affected WordPress site. The changed scope (S:C) in the CVSS vector indicates the impact can extend beyond the plugin itself to affect the broader WordPress environment and site visitors. Confidentiality, integrity, and availability impacts are each rated Low, reflecting limited but real risk to site data and user trust (Patchstack).
No active in-the-wild exploitation has been reported, and no exploit kits or weaponized code are publicly known. The EPSS score is approximately 0.031% (0.000310), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high privileges (Administrator or Developer role) and user interaction, significantly limiting the attack surface (Patchstack).
As of the disclosure date (August 15, 2025), no official patched version of the Dropshix plugin is available. Site administrators should update the plugin as soon as a patched version is released. In the interim, consider deactivating and removing the Dropshix plugin if it is not critical to operations, or restrict administrative access to trusted users only. Web application firewalls (WAFs) with XSS filtering rules can provide additional mitigation while awaiting an official fix (Patchstack).
The vulnerability was flagged by RedPacket Security on social media shortly after disclosure. Patchstack, which coordinated the disclosure, classifies this as low priority with unlikely exploitation impact. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."