Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-67944
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67944 is a Code Injection vulnerability (CWE-94) in the Nelio AB Testing WordPress plugin by Nelio Software, allowing attackers to execute arbitrary code remotely. It affects all versions of the plugin through 8.1.8, with version 8.2.0 released as the patched fix. The vulnerability was reported on November 4, 2025, published by Patchstack on January 20–22, 2026, and assigned a CVSS v3.1 base score of 9.1 (Critical) by Patchstack (Patchstack, NVD).

Technical details

The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), meaning the plugin fails to properly sanitize or restrict user-supplied input before using it in a code generation or evaluation context. Exploitation requires network access and Editor-level privileges within WordPress, with no user interaction needed. The changed scope indicates that a successful exploit can affect resources beyond the vulnerable plugin itself — potentially the broader WordPress installation or server environment. The vulnerability was discovered by security researcher "daroo" and reported through Patchstack's Active VDP program (Patchstack).

Impact

Successful exploitation allows an attacker with Editor-level WordPress privileges to execute arbitrary code on the server, resulting in high confidentiality impact (unauthorized access to sensitive data), high integrity impact (ability to modify data), and high availability impact (potential service disruption), per the updated Patchstack CVSS score. The changed scope means the vulnerability can extend beyond the plugin itself to affect the underlying WordPress site, server, or other hosted resources. This could enable full site takeover, data exfiltration, installation of backdoors, or use of the compromised server in further attacks (Patchstack).

Exploitability

There is no public proof-of-concept exploit or confirmed in-the-wild exploitation as of the latest available data. The EPSS score is approximately 0.029%, reflecting a currently low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this type and severity are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Nelio AB Testing plugin version 8.1.8 or earlier using tools like WPScan, Shodan, or by inspecting plugin metadata in publicly accessible WordPress installations.
  2. Obtain Editor Privileges: Gain Editor-level access to the target WordPress site through credential theft, phishing, brute force, or exploitation of another vulnerability that grants lower-privilege account access.
  3. Identify Vulnerable Input: Navigate to the Nelio AB Testing plugin's administrative interface and locate input fields or configuration options that are processed without proper sanitization.
  4. Inject Malicious Code: Submit a crafted payload containing arbitrary PHP or server-side code through the vulnerable input vector, exploiting the lack of proper code generation controls (CWE-94).
  5. Achieve Code Execution: The injected code is evaluated server-side, granting the attacker arbitrary code execution in the context of the web server, enabling backdoor installation, data exfiltration, or further lateral movement (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing unusual POST requests to Nelio AB Testing plugin endpoints from Editor-level accounts; PHP error logs indicating unexpected code evaluation or execution errors.
  • File System: Newly created or modified PHP files in the WordPress installation directory, particularly in wp-content/plugins/nelio-ab-testing/ or wp-content/uploads/; presence of web shells or obfuscated PHP scripts.
  • Process: Unexpected child processes spawned by the web server process (e.g., curl, wget, bash, python) that are not part of normal WordPress operation.
  • Network: Unusual outbound connections from the web server to external IPs or domains, particularly following administrative activity in the Nelio AB Testing plugin interface.

Mitigation and workarounds

The primary remediation is to update the Nelio AB Testing plugin to version 8.2.0 or later, which contains the fix for this vulnerability (Patchstack). If an immediate upgrade is not possible, consider disabling or removing the plugin until patching can be performed. Restrict Editor-level and higher WordPress roles to trusted users only, and monitor access logs for suspicious activity. Patchstack users can leverage the platform's virtual patching (mitigation rule) to block exploit attempts until the plugin is updated.

Community reactions

Wordfence included this vulnerability in their weekly WordPress vulnerability report for the week of January 19–25, 2026, highlighting it as part of broader WordPress plugin security coverage (Wordfence). Patchstack, the discovering and reporting organization, classified it as medium priority despite the high CVSS score, noting that such vulnerabilities are commonly leveraged in mass-exploit campaigns against WordPress sites (Patchstack). No significant broader media coverage or notable researcher commentary beyond these sources has been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93031HIGH8.8
  • use-your-drive
NoYesSep 18, 2026
CVE-2026-87915HIGH7.2
  • popup-maker
NoYesSep 18, 2026
CVE-2026-18405HIGH7.2
  • jeg-elementor-kit
NoYesSep 18, 2026
CVE-2026-15797MEDIUM6.4
  • popup-maker
NoYesSep 18, 2026
CVE-2026-90884MEDIUM5.4
  • wp-recipe-maker
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management