
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-6055 is a Cross-Site Request Forgery (CSRF) vulnerability in the Zen Sticky Social plugin for WordPress, affecting all versions up to and including 0.3. The flaw stems from missing or incorrect nonce validation on the zen-social-sticky/zen-sticky-social.php page, enabling unauthenticated attackers to update plugin settings and inject malicious web scripts by tricking a site administrator into clicking a crafted link. It was published on June 14, 2025, and reported by Wordfence. The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium) (Wordfence).
The root cause is classified as CWE-352 (Cross-Site Request Forgery), arising from the absence of proper nonce validation in the plugin's settings page handler (zen-social-sticky/zen-sticky-social.php). An attacker can craft a malicious HTML page or link that, when visited by an authenticated WordPress administrator, silently submits a forged POST request to update plugin settings or inject arbitrary JavaScript (stored XSS via CSRF). Exploitation requires no privileges on the target site but does require social engineering to induce administrator interaction. The plugin source code is publicly browsable, facilitating analysis of the vulnerable endpoint (Wordfence, Plugin Source).
Successful exploitation allows an attacker to modify the Zen Sticky Social plugin's settings and inject persistent malicious scripts into the WordPress site, resulting in stored Cross-Site Scripting (XSS) conditions. This can lead to session hijacking, credential theft, redirection of site visitors to malicious domains, or further compromise of the WordPress environment. Both confidentiality and integrity are impacted (low severity each), while availability is unaffected (Wordfence).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2025-6055. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction (an administrator clicking a malicious link), which limits opportunistic mass exploitation (Wordfence).
/wp-admin/options-general.php?page=zen-social-sticky/zen-sticky-social.php or equivalent), including a malicious script payload in a settings field.zen-social-sticky/zen-sticky-social.php) from unusual referrers or external origins.<script> tags or encoded JavaScript payloads in the WordPress database options table (e.g., wp_options entries related to zen-social-sticky).WordPress site administrators should immediately deactivate and remove the Zen Sticky Social plugin (version ≤ 0.3) if no patched version is available from the plugin author. As of the disclosure date, no fixed version has been publicly confirmed; administrators should monitor the WordPress plugin repository for updates. As a general hardening measure, restrict access to the WordPress admin dashboard to trusted IP addresses and ensure administrators are cautious about clicking unsolicited links while authenticated (Wordfence).
The vulnerability was discovered and reported by Wordfence, which published the advisory on June 14, 2025. No significant broader media coverage, researcher commentary, or notable social media discussion has been identified for this vulnerability, consistent with its moderate severity and limited install base.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."