CVE-2025-12066 Overview
The WP Delete Post Copies plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability [CWE-79] affecting all versions up to and including 6.0.2. The flaw stems from insufficient input sanitization and output escaping in the plugin's admin settings. Authenticated attackers with administrator-level permissions can inject arbitrary web scripts that execute whenever a user accesses an injected page. The vulnerability only impacts multi-site installations and installations where the unfiltered_html capability has been disabled.
Critical Impact
Stored script payloads persist in plugin settings and execute in the browser context of any user viewing an affected page, enabling session theft or administrative action hijacking within multi-site networks.
Affected Products
- WP Delete Post Copies plugin for WordPress — all versions through 6.0.2
- WordPress multi-site installations running the affected plugin
- WordPress installations with unfiltered_html disabled
Discovery Timeline
- 2025-11-21 - CVE CVE-2025-12066 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2025-12066
Vulnerability Analysis
The WP Delete Post Copies plugin accepts administrator input through its settings interface without applying sufficient sanitization on save or escaping on output. An administrator who submits crafted markup containing JavaScript causes that payload to be stored in the WordPress database. When another user—including a Super Admin on a multi-site network—loads a page that renders the stored value, the script executes in that user's browser session.
The exploitation precondition narrows the practical attack surface. Standard single-site WordPress administrators already hold the unfiltered_html capability, which permits raw HTML. On multi-site networks, however, individual site administrators do not hold unfiltered_html by default; only Super Admins do. This is the scenario where the privilege boundary is meaningful: a lower-tier site administrator can plant a payload that fires in a Super Admin's session.
Root Cause
The plugin fails to call WordPress sanitization helpers such as sanitize_text_field() or wp_kses() on inbound settings values, and does not apply esc_html() or esc_attr() when echoing those values back into admin pages. This combination allows raw <script> tags or event-handler attributes to round-trip through storage and render as executable markup.
Attack Vector
An authenticated attacker with administrator access to a multi-site subsite submits a crafted value through the plugin's settings form. The payload is persisted and later rendered without escaping. A privileged user accessing the affected admin or front-end page triggers script execution in their session, which an attacker can leverage to perform actions on behalf of that user. The attack requires network access, high privileges, and no user interaction beyond viewing the affected page.
See the Wordfence Vulnerability Report for additional technical context.
Detection Methods for CVE-2025-12066
Indicators of Compromise
- Unexpected <script> tags, javascript: URIs, or on* event handlers stored in WordPress options rows associated with the WP Delete Post Copies plugin.
- Outbound HTTP requests from administrator browsers to unfamiliar domains shortly after visiting the plugin's settings or related admin pages.
- Unexplained creation of new administrator accounts or modification of user roles following administrator sessions.
Detection Strategies
- Audit the wp_options table (or network-level wp_sitemeta) for plugin-owned keys containing HTML or JavaScript markup.
- Review WordPress audit logs for settings changes made by lower-tier site administrators that touch the plugin configuration.
- Compare installed plugin version against 6.0.2 and flag any installation at or below that version on multi-site networks.
Monitoring Recommendations
- Monitor administrator sessions for anomalous XHR or fetch activity originating from /wp-admin/ pages.
- Enable file integrity and database change monitoring on multi-site WordPress networks.
- Alert on new privileged user creation or capability grants occurring within a short window after plugin settings edits.
How to Mitigate CVE-2025-12066
Immediate Actions Required
- Update the WP Delete Post Copies plugin to a version later than 6.0.2 as soon as a patched release is available.
- On multi-site networks, restrict plugin settings access to Super Admins where feasible until the patch is applied.
- Review the plugin's stored settings and remove any entries containing script content or inline event handlers.
Patch Information
A code change for the plugin is referenced in the WordPress Plugin Changeset. Administrators should install the updated plugin release from the WordPress plugin repository once published and verify the active version in the admin dashboard.
Workarounds
- Deactivate the WP Delete Post Copies plugin on multi-site installations until an updated release is deployed.
- Enforce a Content Security Policy (CSP) that disallows inline script execution in /wp-admin/ to blunt stored XSS payloads.
- Limit which users on multi-site networks can administer plugins by tightening role assignments.
# Verify installed plugin version and deactivate network-wide if vulnerable
wp plugin get etruel-del-post-copies --field=version
wp plugin deactivate etruel-del-post-copies --network
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.