Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-6055
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-6055 is a Cross-Site Request Forgery (CSRF) vulnerability in the Zen Sticky Social plugin for WordPress, affecting all versions up to and including 0.3. The flaw stems from missing or incorrect nonce validation on the zen-social-sticky/zen-sticky-social.php page, enabling unauthenticated attackers to update plugin settings and inject malicious web scripts by tricking a site administrator into clicking a crafted link. It was published on June 14, 2025, and reported by Wordfence. The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium) (Wordfence).

Technical details

The root cause is classified as CWE-352 (Cross-Site Request Forgery), arising from the absence of proper nonce validation in the plugin's settings page handler (zen-social-sticky/zen-sticky-social.php). An attacker can craft a malicious HTML page or link that, when visited by an authenticated WordPress administrator, silently submits a forged POST request to update plugin settings or inject arbitrary JavaScript (stored XSS via CSRF). Exploitation requires no privileges on the target site but does require social engineering to induce administrator interaction. The plugin source code is publicly browsable, facilitating analysis of the vulnerable endpoint (Wordfence, Plugin Source).

Impact

Successful exploitation allows an attacker to modify the Zen Sticky Social plugin's settings and inject persistent malicious scripts into the WordPress site, resulting in stored Cross-Site Scripting (XSS) conditions. This can lead to session hijacking, credential theft, redirection of site visitors to malicious domains, or further compromise of the WordPress environment. Both confidentiality and integrity are impacted (low severity each), while availability is unaffected (Wordfence).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2025-6055. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction (an administrator clicking a malicious link), which limits opportunistic mass exploitation (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Zen Sticky Social plugin (version ≤ 0.3) via web crawling, WordPress plugin enumeration tools, or passive fingerprinting.
  2. Craft malicious request: Construct an HTML page containing a hidden form or auto-submitting JavaScript that sends a POST request to the target WordPress admin endpoint for the Zen Sticky Social settings page (/wp-admin/options-general.php?page=zen-social-sticky/zen-sticky-social.php or equivalent), including a malicious script payload in a settings field.
  3. Social engineering: Deliver the crafted page to a WordPress site administrator via phishing email, forum post, or other means, inducing them to visit the attacker-controlled URL while authenticated to their WordPress dashboard.
  4. Payload execution: Upon the administrator loading the page, the forged request is submitted automatically, updating plugin settings and injecting the malicious script into the site. The script then executes in the browsers of subsequent site visitors, enabling session theft, credential harvesting, or further attacks (Wordfence).

Indicators of compromise

  • Logs: WordPress access logs showing unexpected POST requests to the Zen Sticky Social settings page (zen-social-sticky/zen-sticky-social.php) from unusual referrers or external origins.
  • File System: Unexpected or modified plugin settings containing <script> tags or encoded JavaScript payloads in the WordPress database options table (e.g., wp_options entries related to zen-social-sticky).
  • Network: Outbound connections from site visitors' browsers to unknown or attacker-controlled domains following visits to affected WordPress pages, potentially indicating injected script execution.

Mitigation and workarounds

WordPress site administrators should immediately deactivate and remove the Zen Sticky Social plugin (version ≤ 0.3) if no patched version is available from the plugin author. As of the disclosure date, no fixed version has been publicly confirmed; administrators should monitor the WordPress plugin repository for updates. As a general hardening measure, restrict access to the WordPress admin dashboard to trusted IP addresses and ensure administrators are cautious about clicking unsolicited links while authenticated (Wordfence).

Community reactions

The vulnerability was discovered and reported by Wordfence, which published the advisory on June 14, 2025. No significant broader media coverage, researcher commentary, or notable social media discussion has been identified for this vulnerability, consistent with its moderate severity and limited install base.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93031HIGH8.8
  • use-your-drive
NoYesSep 18, 2026
CVE-2026-87915HIGH7.2
  • popup-maker
NoYesSep 18, 2026
CVE-2026-18405HIGH7.2
  • jeg-elementor-kit
NoYesSep 18, 2026
CVE-2026-15797MEDIUM6.4
  • popup-maker
NoYesSep 18, 2026
CVE-2026-90884MEDIUM5.4
  • wp-recipe-maker
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management