CVE-2025-6378 Overview
CVE-2025-6378 is a Stored Cross-Site Scripting (XSS) vulnerability in the Responsive Food and Drink Menu plugin for WordPress. The flaw affects all versions of the plugin up to and including 2.3. The vulnerability resides in the display_pdf_menus shortcode, which fails to properly sanitize user-supplied attributes and escape output. Authenticated attackers with contributor-level access or higher can inject arbitrary JavaScript into pages. The injected scripts execute in the browser of any visitor who accesses the affected page. The issue is tracked under CWE-79 (Improper Neutralization of Input During Web Page Generation).
Critical Impact
Contributor-level users can inject persistent JavaScript that executes against any site visitor, enabling session theft, administrative account compromise, and site defacement.
Affected Products
- Corporatezen Responsive Food and Drink Menu plugin for WordPress, versions up to and including 2.3
- WordPress sites permitting contributor-level or higher registration
- Any page or post rendering the vulnerable display_pdf_menus shortcode
Discovery Timeline
- 2025-06-26 - CVE-2025-6378 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-6378
Vulnerability Analysis
The Responsive Food and Drink Menu plugin registers a shortcode named display_pdf_menus that accepts user-controlled attributes. The shortcode handler renders these attributes into the resulting HTML without sufficient input sanitization or output escaping. An authenticated user with contributor privileges can craft a post or page containing the shortcode with malicious attribute values. When the shortcode is processed, the attacker-supplied payload is embedded directly into the DOM. Any user who subsequently views the page executes the injected script under the site's origin. This grants the attacker access to cookies, session tokens, and any actions available to the viewing user, including administrators.
Root Cause
The root cause is missing input validation and missing output encoding on shortcode attributes processed by the display_pdf_menus handler. WordPress provides helper functions such as esc_attr(), esc_html(), and wp_kses() for encoding output, but the plugin does not apply them to the affected attributes. This classifies as [CWE-79], improper neutralization of input during web page generation.
Attack Vector
Exploitation requires an authenticated account at contributor level or above. The attacker creates or edits a post that embeds the display_pdf_menus shortcode with a JavaScript payload in one of its vulnerable attributes. Once the post is published, previewed, or viewed by a higher-privileged user such as an editor or administrator, the payload executes in that user's browser context. This can be chained to hijack administrator sessions, create rogue accounts, or plant additional persistence mechanisms on the site.
No verified proof-of-concept code is publicly available. Refer to the Wordfence Vulnerability Report for further technical detail.
Detection Methods for CVE-2025-6378
Indicators of Compromise
- Posts or pages containing [display_pdf_menus] shortcode with attribute values containing HTML tags such as <script>, onerror=, onload=, or javascript: URIs
- Unexpected outbound requests from visitor browsers to attacker-controlled domains originating from pages rendering the shortcode
- New WordPress administrator accounts or role changes following contributor account activity
- Unusual JavaScript observed in the post_content column of the wp_posts table for entries authored by contributor-level users
Detection Strategies
- Query the WordPress database for posts containing the display_pdf_menus shortcode and inspect attribute values for HTML or script content
- Monitor web server access logs for requests to pages using the vulnerable shortcode that produce anomalous response sizes
- Review WordPress audit logs for post creation and edit events performed by contributor-level users
- Deploy a Web Application Firewall (WAF) with rules that block script content in shortcode attributes
Monitoring Recommendations
- Enable file integrity monitoring on the wp-content/plugins/responsive-food-and-drink-menu/ directory
- Log and alert on new user registrations and role escalations within WordPress
- Track Content Security Policy (CSP) violation reports to identify inline script injection attempts
- Correlate authentication events for administrator accounts with recent contributor activity to detect session hijacking
How to Mitigate CVE-2025-6378
Immediate Actions Required
- Update the Responsive Food and Drink Menu plugin to a version later than 2.3 once the vendor publishes a fix
- If no patched version is available, deactivate and remove the plugin from all WordPress installations
- Audit all existing posts and pages for the display_pdf_menus shortcode and review attribute contents for malicious payloads
- Rotate credentials and session tokens for administrator accounts that may have viewed injected content
Patch Information
At the time of NVD publication, all versions up to and including 2.3 are affected. Check the WordPress plugin developer page for updated releases and changelog entries confirming a fix for the display_pdf_menus shortcode sanitization issue.
Workarounds
- Restrict contributor-level and higher access to trusted users only; review and remove unnecessary accounts
- Deploy a Web Application Firewall with rulesets targeting stored XSS in WordPress shortcodes
- Implement a strict Content Security Policy that disallows inline scripts and restricts script sources to trusted origins
- Remove all instances of the display_pdf_menus shortcode from published content until a patched version is installed
# Search WordPress database for use of the vulnerable shortcode
wp db query "SELECT ID, post_title, post_author FROM wp_posts \
WHERE post_content LIKE '%[display_pdf_menus%' \
AND post_status IN ('publish','draft','pending');"
# Deactivate the plugin via WP-CLI as a temporary mitigation
wp plugin deactivate responsive-food-and-drink-menu
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
