
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67944 is a Code Injection vulnerability (CWE-94) in the Nelio AB Testing WordPress plugin by Nelio Software, allowing attackers to execute arbitrary code remotely. It affects all versions of the plugin through 8.1.8, with version 8.2.0 released as the patched fix. The vulnerability was reported on November 4, 2025, published by Patchstack on January 20–22, 2026, and assigned a CVSS v3.1 base score of 9.1 (Critical) by Patchstack (Patchstack, NVD).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), meaning the plugin fails to properly sanitize or restrict user-supplied input before using it in a code generation or evaluation context. Exploitation requires network access and Editor-level privileges within WordPress, with no user interaction needed. The changed scope indicates that a successful exploit can affect resources beyond the vulnerable plugin itself — potentially the broader WordPress installation or server environment. The vulnerability was discovered by security researcher "daroo" and reported through Patchstack's Active VDP program (Patchstack).
Successful exploitation allows an attacker with Editor-level WordPress privileges to execute arbitrary code on the server, resulting in high confidentiality impact (unauthorized access to sensitive data), high integrity impact (ability to modify data), and high availability impact (potential service disruption), per the updated Patchstack CVSS score. The changed scope means the vulnerability can extend beyond the plugin itself to affect the underlying WordPress site, server, or other hosted resources. This could enable full site takeover, data exfiltration, installation of backdoors, or use of the compromised server in further attacks (Patchstack).
There is no public proof-of-concept exploit or confirmed in-the-wild exploitation as of the latest available data. The EPSS score is approximately 0.029%, reflecting a currently low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this type and severity are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).
wp-content/plugins/nelio-ab-testing/ or wp-content/uploads/; presence of web shells or obfuscated PHP scripts.curl, wget, bash, python) that are not part of normal WordPress operation.The primary remediation is to update the Nelio AB Testing plugin to version 8.2.0 or later, which contains the fix for this vulnerability (Patchstack). If an immediate upgrade is not possible, consider disabling or removing the plugin until patching can be performed. Restrict Editor-level and higher WordPress roles to trusted users only, and monitor access logs for suspicious activity. Patchstack users can leverage the platform's virtual patching (mitigation rule) to block exploit attempts until the plugin is updated.
Wordfence included this vulnerability in their weekly WordPress vulnerability report for the week of January 19–25, 2026, highlighting it as part of broader WordPress plugin security coverage (Wordfence). Patchstack, the discovering and reporting organization, classified it as medium priority despite the high CVSS score, noting that such vulnerabilities are commonly leveraged in mass-exploit campaigns against WordPress sites (Patchstack). No significant broader media coverage or notable researcher commentary beyond these sources has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."