CVE-2026-25489: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-25489 is a stored cross-site scripting (XSS) vulnerability in Craft Commerce, an ecommerce plugin for Craft CMS, that allows authenticated attackers with high privileges to execute malicious JavaScript in an administrator's browser. The vulnerability affects versions 4.0.0-RC1 through 4.10.0 and 5.0.0 through 5.5.1, and was disclosed on February 2, 2026. It carries a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4.0 base score of 6.1 (Medium) (Github Advisory, Feedly).

Technical details

The root cause is improper output encoding (CWE-79) — the Name and Description fields in Tax Zones are rendered in the admin panel without HTML encoding, allowing stored JavaScript payloads to execute in the browser of any administrator who views the Tax Zones listing page. The fix, applied in commit fa27333, wraps affected field values with Html::encode() across multiple controllers including TaxZonesController.php, ShippingZonesController.php, TaxCategoriesController.php, TaxRatesController.php, and others (Patch Commit). Exploitation requires the attacker to hold specific Craft Commerce permissions: access to the control panel, "Manage store settings," and "Manage taxes" (Github Advisory).

Impact

A successful exploit allows an attacker to execute arbitrary JavaScript in the context of an administrator's browser session, enabling session hijacking, credential theft via fake login overlays, and unauthorized administrative actions. Critically, the advisory demonstrates a privilege escalation path: a malicious payload can silently elevate the attacker's account to full administrator if an admin views the Tax Zones page during an elevated session. This could result in complete compromise of the Craft Commerce installation, including access to customer data, order information, and store configuration (Github Advisory).

Exploitability

A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, including specific payload examples and privilege escalation steps. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.043% (0.000430), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory, Feedly).

Exploitation steps

  1. Obtain required permissions: Acquire a Craft Commerce account with the following permissions: access to the control panel, "Manage store settings," and "Manage taxes."
  2. Navigate to Tax Zones: Log in to the admin panel and go to Commerce → Store Management → Tax Zones (/admin/commerce/store-management/primary/taxzones).
  3. Inject XSS payload: Create a new Tax Zone and enter a malicious JavaScript payload (e.g., <script>alert(1)</script> for proof-of-concept, or a credential-harvesting/session-hijacking script) in the Name or Description field, then click Save.
  4. Trigger execution: When an administrator navigates to the Tax Zones listing page, the stored payload executes in their browser within the trusted admin domain.
  5. Privilege escalation (advanced): Replace the basic payload with a script that calls the Craft CMS API to elevate the attacker's user account to Administrator, using the admin's active elevated session. Alternatively, inject a fake "Session Expired" login modal overlay to capture the administrator's credentials directly, since the overlay appears on the trusted domain (Github Advisory).

Indicators of compromise

  • Logs: Admin panel access logs showing requests to /admin/commerce/store-management/primary/taxzones from unexpected or low-privileged user accounts; POST requests to Tax Zone creation/edit endpoints containing HTML or JavaScript tags in name/description parameters.
  • Application Data: Tax Zone Name or Description fields in the database containing HTML tags, <script> elements, JavaScript event handlers (e.g., onerror, onload), or encoded variants thereof.
  • Network: Outbound requests from the admin browser to unexpected external domains (e.g., attacker-controlled servers) originating from admin panel page loads, potentially carrying session tokens or credentials.
  • User Account Changes: Unexpected elevation of non-administrator accounts to administrator role in Craft CMS user management logs, particularly if correlated with admin visits to the Tax Zones page (Github Advisory).

Mitigation and workarounds

Upgrade Craft Commerce to version 4.10.1 (for the 4.x branch) or 5.5.2 (for the 5.x branch), which apply proper HTML encoding to all affected fields (Release 4.10.1, Release 5.5.2). If immediate patching is not possible, restrict the "Manage store settings" and "Manage taxes" permissions to only fully trusted administrators, minimizing the pool of accounts that could inject payloads. Monitor admin panel access logs for suspicious activity on Tax Zone management pages until the patch is applied (Github Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management