
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-52755 is a Reflected Cross-Site Scripting (XSS) vulnerability in the "Child Themes" WordPress plugin developed by Chris Taylor. It affects all versions up to and including 1.0.1, with no official patch currently available. The vulnerability was reported by researcher Nguyen Xuan Chien on July 22, 2025, published by Patchstack on August 21, 2025, and assigned a CVE on October 22, 2025. It carries a CVSS v3.1 base score of 7.1 (High) (Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a Reflected XSS variant. User-supplied input is not properly sanitized or escaped before being reflected back in the plugin's generated web page output, allowing an attacker to inject arbitrary JavaScript. Exploitation requires no authentication (unauthenticated attacker) but does require user interaction — a victim must click a crafted malicious link or visit an attacker-controlled page that triggers the request. The vulnerability is categorized under OWASP Top 10 A3: Injection (Patchstack).
Successful exploitation allows an attacker to inject and execute malicious scripts in the context of a victim's browser session on the affected WordPress site. This can lead to session hijacking, credential theft, redirection to malicious sites, defacement of web content visible to the victim, or delivery of further malware payloads. The CVSS scope is marked as "Changed," indicating the impact extends beyond the vulnerable component itself, affecting confidentiality, integrity, and availability at a low level each (Patchstack).
No public proof-of-concept exploit code has been identified at this time, and there is no evidence of active in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.029%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).
?param=<script>malicious_code</script> to the relevant plugin endpoint).%3Cscript%3E, onerror=, onload=) in query parameters.As of the time of publication, no official patch has been released by the plugin developer for the Child Themes plugin. The recommended immediate action is to deactivate and remove the Child Themes plugin (versions ≤ 1.0.1) from affected WordPress installations. Patchstack has issued a virtual patching/mitigation rule for subscribers to block exploitation attempts until an official fix is available. Site administrators should monitor the WordPress plugin repository for an updated version and apply it promptly when released (Patchstack).
The vulnerability was discovered and responsibly disclosed by security researcher Nguyen Xuan Chien and coordinated through Patchstack's Vulnerability Disclosure Program (VDP). Patchstack classified it as medium priority and noted the risk of mass-exploit campaigns targeting WordPress plugins of this type. No significant broader media coverage or notable social media commentary has been identified beyond the Patchstack advisory (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."