CVE-2025-6382 Overview
CVE-2025-6382 is a Stored Cross-Site Scripting (XSS) vulnerability in the Taeggie Feed plugin for WordPress, affecting all versions up to and including 0.1.10. The flaw resides in the plugin's taeggie-feed shortcode, where the render() method injects the user-supplied name attribute directly into a <script> tag without proper escaping. Authenticated attackers with contributor-level access or above can inject arbitrary JavaScript that executes when other users visit affected pages. The issue is tracked under CWE-79 (Improper Neutralization of Input During Web Page Generation).
Critical Impact
Contributor-level users can inject persistent JavaScript that executes in the browser session of any visitor, including administrators, enabling session theft, account takeover, or redirection to malicious content.
Affected Products
- Taeggie Feed WordPress plugin, versions ≤ 0.1.10
- WordPress sites permitting contributor-level or higher authenticated users
- Any site rendering pages that include the taeggie-feed shortcode
Discovery Timeline
- 2025-07-24 - CVE-2025-6382 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-6382
Vulnerability Analysis
The Taeggie Feed plugin exposes a shortcode named taeggie-feed that accepts a name attribute from the content editor. Inside the plugin's render() method, this attribute is concatenated into an HTML <script> block. Specifically, the value is placed into the id attribute of the script element and passed into a jQuery.getScript() call. Because the plugin does not apply contextual escaping, an attacker controls raw JavaScript context and can break out of both the attribute and the function argument.
The stored nature of the flaw amplifies the impact. Any post or page saved with a malicious shortcode payload will execute the injected script every time an authenticated or unauthenticated visitor loads that page. In WordPress, contributor-level accounts can create draft posts, and if an editor or administrator previews the content, the payload runs in their privileged session.
Root Cause
The root cause is missing output encoding on user-controlled input. Values destined for a JavaScript execution context require encoding through functions such as esc_js() or wp_json_encode(), not the default HTML escaping used elsewhere in WordPress. The plugin's render() method treats the name attribute as trusted string data and interpolates it into a <script> tag.
Attack Vector
Exploitation requires an authenticated account with contributor privileges or higher. The attacker inserts the taeggie-feed shortcode into post content and supplies a crafted name attribute containing script-terminating characters followed by arbitrary JavaScript. When the post is rendered, the payload executes in the visitor's browser under the site's origin. See the Wordfence Vulnerability Report and the WordPress Plugin Source Code for the vulnerable implementation details.
No public proof-of-concept exploit is currently listed for CVE-2025-6382. Refer to the referenced advisories for technical specifics.
Detection Methods for CVE-2025-6382
Indicators of Compromise
- Post or page content containing taeggie-feed shortcode with unusual characters in the name attribute, such as quotes, angle brackets, or </script> sequences.
- Outbound requests from visitor browsers to unfamiliar domains originating from pages that render the shortcode.
- New or modified posts authored by contributor-level accounts that reference the plugin's shortcode.
Detection Strategies
- Audit the wp_posts table for shortcode usage with SQL such as searches for taeggie-feed combined with characters like <, >, or javascript:.
- Enable web application firewall rules that inspect POST bodies to wp-admin/post.php for shortcode attributes containing script metacharacters.
- Review WordPress activity logs for contributor accounts creating or editing posts that embed the affected shortcode.
Monitoring Recommendations
- Monitor role changes and new contributor account creation, as attackers often leverage low-privilege accounts to reach stored XSS conditions.
- Track browser console errors and Content Security Policy (CSP) violations reported from pages that include third-party plugin shortcodes.
- Alert on administrator sessions that preview draft content authored by non-trusted users.
How to Mitigate CVE-2025-6382
Immediate Actions Required
- Deactivate the Taeggie Feed plugin if a patched release is not yet deployed on the site.
- Restrict contributor and author roles to trusted users only, and review recent role assignments.
- Scan existing posts and pages for the taeggie-feed shortcode and inspect the name attribute for suspicious content.
Patch Information
A code change addressing the input handling was committed to the plugin repository. Refer to WordPress Changeset #3336357 for the fix and update to the latest available version tracked at the WordPress plugin page. Sites still running version 0.1.10 or earlier remain vulnerable.
Workarounds
- Remove the plugin entirely if it is not actively used on the site.
- Deploy a WAF rule that blocks shortcode attributes containing <, >, or " characters when submitted through the WordPress editor.
- Enforce a strict Content Security Policy that disallows inline scripts and untrusted external script sources to reduce XSS impact.
# Configuration example: quickly disable the plugin via WP-CLI
wp plugin deactivate taeggie-feed
wp plugin delete taeggie-feed
# Search all posts for the vulnerable shortcode
wp db query "SELECT ID, post_title FROM wp_posts WHERE post_content LIKE '%[taeggie-feed%'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
