CVE-2025-67550 Overview
CVE-2025-67550 is a stored cross-site scripting (XSS) vulnerability in the rhewlif Donation Thermometer plugin for WordPress. The flaw affects all versions up to and including 2.2.6. An authenticated attacker with low privileges can inject malicious script content that persists in the plugin's stored data. When other users render affected pages, the browser executes the injected script in their session context.
The issue is classified under CWE-79, Improper Neutralization of Input During Web Page Generation. The scope-changed CVSS vector indicates the payload can affect resources beyond the vulnerable component, such as browser sessions of visitors and administrators.
Critical Impact
Authenticated attackers can inject persistent JavaScript that executes in the browsers of site visitors and administrators, enabling session theft, credential harvesting, and administrative account takeover.
Affected Products
- rhewlif Donation Thermometer plugin (donation-thermometer) for WordPress
- All versions from n/a through 2.2.6
- WordPress sites with the plugin activated and accepting authenticated contributions
Discovery Timeline
- 2025-12-09 - CVE-2025-67550 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-67550
Vulnerability Analysis
The Donation Thermometer plugin fails to neutralize user-controlled input before storing it and rendering it back into generated web pages. This produces a stored XSS condition where an authenticated user with editing rights can persist a JavaScript payload inside plugin fields. The payload executes whenever another user, including administrators, loads a page that renders the affected value.
Exploitation requires low privileges and user interaction, such as loading a WordPress admin page or a front-end view that displays the injected content. Because the vulnerability changes trust scope, script execution occurs in the browser context of the victim rather than the attacker. This allows the attacker to abuse the victim's authenticated session, perform administrative actions, or pivot to further compromise.
Refer to the Patchstack Vulnerability Analysis for additional technical details.
Root Cause
The root cause is missing output encoding and inadequate input sanitization on plugin fields that accept user-supplied text. WordPress provides helpers such as wp_kses, esc_html, and esc_attr for safe rendering; the plugin does not consistently apply these before writing values into the DOM. Persisted values are echoed into HTML contexts without contextual escaping, so <script> tags and event handlers survive to execution.
Attack Vector
The attack is network-based and requires an authenticated low-privileged account on the target WordPress site. The attacker submits a crafted value through a plugin form or endpoint that stores donation thermometer data. When a legitimate user later views a page that renders the value, the injected script runs with the victim's browser privileges. The scope change enables the attacker to reach cookies, tokens, and DOM elements outside the plugin's own boundary.
No verified public proof-of-concept code is available. See the Patchstack advisory for further technical context.
Detection Methods for CVE-2025-67550
Indicators of Compromise
- Unexpected <script> tags, on* event handlers, or javascript: URIs stored in Donation Thermometer plugin options or post metadata
- New or modified WordPress administrator accounts created shortly after low-privileged users interact with the plugin
- Outbound requests from administrator browsers to unfamiliar domains that correlate with viewing pages containing the plugin's output
Detection Strategies
- Audit the WordPress database (wp_options, wp_postmeta) for plugin-related rows containing HTML or JavaScript syntax
- Deploy a Web Application Firewall rule to flag requests to plugin endpoints that contain script tags or encoded XSS payloads
- Enable and review WordPress activity logging for plugin configuration changes made by contributors, authors, or editors
Monitoring Recommendations
- Monitor Content Security Policy violation reports for inline script executions originating from pages that render Donation Thermometer content
- Track authenticated session anomalies, such as administrator sessions performing unexpected privilege changes
- Alert on installation of unknown plugins or themes shortly after authenticated user activity on the donation thermometer interface
How to Mitigate CVE-2025-67550
Immediate Actions Required
- Deactivate the Donation Thermometer plugin on any WordPress site running version 2.2.6 or earlier until a patched release is confirmed
- Review all existing plugin data and remove any stored values containing HTML or JavaScript content
- Rotate credentials and invalidate active sessions for administrator accounts that may have viewed injected content
Patch Information
At the time of writing, the CVE record lists all versions up to and including 2.2.6 as affected, and no fixed version is identified in the available advisory data. Monitor the Patchstack advisory and the WordPress plugin repository for an updated release, and apply it as soon as it becomes available.
Workarounds
- Restrict plugin usage to trusted administrator accounts and remove contributor or author access to plugin configuration
- Implement a strict Content Security Policy that blocks inline scripts and restricts allowed script sources
- Place the WordPress admin interface behind IP allow-listing or multi-factor authentication to reduce exposure of privileged sessions
# Example: enforce Content Security Policy via Apache to limit inline script execution
Header set Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
