CVE-2025-6673 Overview
The Easy Restaurant Menu Manager plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability in versions up to and including 2.0.1. The flaw resides in the nsc_eprm_menu_link shortcode, which fails to properly sanitize user-supplied attributes or escape output. Authenticated users with contributor-level access or higher can inject arbitrary JavaScript into pages. The injected scripts execute in the browsers of any visitors who access the affected pages. This vulnerability is tracked as CWE-79 and carries a CVSS score of 6.4.
Critical Impact
Authenticated contributors can persistently store malicious JavaScript that executes against site visitors and administrators, enabling session hijacking, credential theft, and account takeover.
Affected Products
- Easy Restaurant Menu Manager (easy-pdf-restaurant-menu-upload) WordPress plugin
- All versions up to and including 2.0.1
- Sites where contributor-level accounts or higher can insert shortcodes
Discovery Timeline
- 2025-07-04 - CVE-2025-6673 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-6673
Vulnerability Analysis
The vulnerability affects the nsc_eprm_menu_link shortcode handler registered by the plugin. Shortcode attributes accepted from post or page content are rendered back into the DOM without proper sanitization or contextual output escaping. Because WordPress persists post content in the database, injected payloads survive across sessions and execute for every visitor rendering the page. The stored nature of this XSS elevates its impact compared to reflected variants.
Exploitation requires an authenticated account with at least contributor privileges. Contributor is a low-trust role widely granted on multi-author WordPress sites, which broadens the realistic attack surface. Successful exploitation runs script in the security context of the site origin, giving the attacker access to cookies, session tokens, and any client-side APIs available to the victim.
Root Cause
The root cause is missing input sanitization on shortcode attribute values combined with unsafe output rendering. The plugin passes attribute values through to HTML output without functions such as esc_attr(), esc_html(), esc_url(), or wp_kses(). Any HTML-significant characters supplied by the shortcode author are emitted verbatim, allowing script tags, event handlers, or javascript: URIs to break out of the intended attribute context. Details of the vulnerable code path are documented in the WordPress Plugin Code Review.
Attack Vector
An attacker with contributor access authors a post containing the nsc_eprm_menu_link shortcode with malicious attribute values. Once an editor previews, an administrator reviews, or a visitor loads the page, the payload executes. Typical payloads target administrator sessions to create new admin users, install backdoor plugins, or exfiltrate data. See the Wordfence Vulnerability Report for additional exploitation context.
// No verified public exploit code available.
// The vulnerability is triggered by supplying attacker-controlled
// attribute values to the nsc_eprm_menu_link shortcode, which are
// then rendered without escaping into the page output.
Detection Methods for CVE-2025-6673
Indicators of Compromise
- Post or page content containing [nsc_eprm_menu_link] shortcodes with attribute values that include <script>, onerror, onload, or javascript: strings.
- Unexpected creation of new WordPress administrator accounts following contributor post submissions.
- Outbound requests from visitor browsers to unfamiliar domains after loading pages that embed the plugin's shortcode.
- Modification timestamps on wp_posts rows authored by contributor-role accounts that coincide with anomalous admin activity.
Detection Strategies
- Query the WordPress database for shortcode usage: SELECT ID, post_author, post_title FROM wp_posts WHERE post_content LIKE '%nsc_eprm_menu_link%'; and inspect attribute values.
- Monitor web server logs for requests to pages containing the shortcode paired with suspicious Referer or query patterns.
- Deploy a web application firewall rule to flag responses containing script content within shortcode-rendered attributes.
- Correlate contributor-role publish events with subsequent privileged actions in WordPress audit logs.
Monitoring Recommendations
- Enable a WordPress activity logging plugin to capture post edits, role changes, and plugin installations tied to contributor accounts.
- Alert on the appearance of <script> tags or event-handler attributes inside post_content rows.
- Track outbound Content Security Policy (CSP) violation reports if CSP is deployed, focusing on inline-script blocks.
How to Mitigate CVE-2025-6673
Immediate Actions Required
- Update the Easy Restaurant Menu Manager plugin to a version later than 2.0.1 that includes the fix from WordPress Plugin Changeset 3318491.
- Audit existing posts and pages for malicious nsc_eprm_menu_link shortcode attribute values and remove any injected payloads.
- Review contributor and author accounts, rotating credentials on any account that shows signs of compromise or unexpected activity.
- Force a password reset for administrator accounts if evidence of session-token theft is found.
Patch Information
The vendor patched the vulnerability in the changeset referenced by the WordPress Plugin Changeset. Site administrators should upgrade through the WordPress plugin updater or by replacing the plugin files with the patched release. Verify the installed version reports higher than 2.0.1 after upgrade.
Workarounds
- Restrict the contributor role from using shortcodes by filtering the_content through strip_shortcodes() for untrusted authors until patched.
- Deactivate the Easy Restaurant Menu Manager plugin if a patched version cannot be installed immediately.
- Enforce a strict Content Security Policy that disallows inline scripts to limit the impact of stored XSS payloads.
- Require editorial review before publishing any post authored by a contributor.
# Update the plugin from WP-CLI
wp plugin update easy-pdf-restaurant-menu-upload
# Verify installed version
wp plugin get easy-pdf-restaurant-menu-upload --field=version
# Temporarily deactivate if a patched version is unavailable
wp plugin deactivate easy-pdf-restaurant-menu-upload
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
