Skip to main content

CVE-2025-7354: WP Shortcodes Plugin XSS Vulnerability

CVE-2025-7354 is a stored cross-site scripting vulnerability in WP Shortcodes Plugin for WordPress that enables authenticated attackers to inject malicious scripts. This article covers technical details, impact assessment, and remediation.

Published:

CVE-2025-7354 Overview

CVE-2025-7354 is a Stored Cross-Site Scripting (XSS) vulnerability in the WP Shortcodes Plugin — Shortcodes Ultimate for WordPress. The flaw affects all versions up to and including 7.4.2. It stems from insufficient input sanitization and output escaping on user-supplied attributes passed to several plugin shortcodes. Authenticated users with contributor-level access or above can inject arbitrary JavaScript into pages. The payload executes in the browser of any visitor who views the affected page. The vulnerability is tracked under CWE-79 and was addressed in WordPress Changeset #3328729.

Critical Impact

Contributor-level accounts can inject persistent scripts into published pages, enabling session theft, admin account takeover, and drive-by redirection of site visitors.

Affected Products

  • WP Shortcodes Plugin — Shortcodes Ultimate for WordPress, versions ≤ 7.4.2
  • Vulnerable shortcodes include button, expand, members, post, and user
  • Any WordPress site permitting contributor-or-higher registration with the plugin active

Discovery Timeline

  • 2025-07-21 - CVE-2025-7354 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-7354

Vulnerability Analysis

Shortcodes Ultimate registers dozens of shortcodes that render HTML based on attributes an author supplies inside post content. Several handlers echo those attributes into markup without escaping them for the HTML context. An authenticated contributor can craft a shortcode where an attribute value contains an event handler or a script-bearing string. When an editor previews or a visitor loads the resulting page, the browser parses the injected markup and executes attacker-controlled JavaScript. Because the payload is stored in post content, every subsequent view triggers execution, making the impact persistent across sessions and users.

Root Cause

The root cause is missing output escaping in shortcode render callbacks. The vulnerable code paths are visible in the plugin source at button.php L408, expand.php L130, members.php L79, post.php L116, and user.php L95. Attribute values reach the DOM without being passed through esc_attr() or esc_html(), so any character that closes an attribute or opens a tag is honored by the browser.

Attack Vector

Exploitation requires an authenticated WordPress account with edit_posts capability, which contributors have by default. The attacker creates or edits a post containing one of the vulnerable shortcodes and supplies a malicious attribute value. Once the post is viewed, typically after an editor publishes it or an admin previews it, the script fires in the victim's authenticated context. Attackers commonly use this primitive to exfiltrate session cookies, add a new administrator account through WordPress REST endpoints, or plant SEO spam. See the Wordfence Vulnerability Report for additional analysis.

No public proof-of-concept code has been released. Refer to the plugin source references above for the exact injection points.

Detection Methods for CVE-2025-7354

Indicators of Compromise

  • Post or page content containing Shortcodes Ultimate tags such as [su_button], [su_expand], [su_members], [su_post], or [su_user] with attributes that include ", <, onerror=, onclick=, or javascript: sequences.
  • Newly created administrator accounts appearing shortly after a contributor publishes or updates content.
  • Unexpected outbound requests from editor or visitor browsers to third-party domains when viewing plugin-rendered pages.

Detection Strategies

  • Query the wp_posts table for shortcode attribute values containing HTML control characters or script keywords.
  • Compare the installed plugin version against 7.4.3 or later across all managed WordPress sites.
  • Review audit logs for contributor accounts that submitted posts using the affected shortcodes during the vulnerable window.

Monitoring Recommendations

  • Alert on WordPress role changes, especially promotions to administrator, following contributor post activity.
  • Monitor web server logs for anomalous JavaScript payloads in cached page responses.
  • Enable a Web Application Firewall (WAF) rule set that inspects shortcode attribute payloads for XSS patterns.

How to Mitigate CVE-2025-7354

Immediate Actions Required

  • Update the Shortcodes Ultimate plugin to version 7.4.3 or later on every WordPress installation.
  • Audit all contributor, author, and editor accounts and disable any that are inactive or unrecognized.
  • Review recent posts using the affected shortcodes and remove attribute values containing HTML or JavaScript.

Patch Information

The vendor addressed the vulnerability in WordPress Changeset #3328729, which introduces proper escaping on the affected shortcode attributes. Upgrading to version 7.4.3 or newer via the WordPress plugin updater applies the fix.

Workarounds

  • Restrict post creation and editing capabilities to trusted administrators until the patch is applied.
  • Deploy a WAF rule that blocks shortcode attributes containing <script, on*=, or javascript: substrings.
  • Temporarily deactivate the Shortcodes Ultimate plugin if immediate patching is not possible.
bash
# Update Shortcodes Ultimate on the affected WordPress site using WP-CLI
wp plugin update shortcodes-ultimate --version=7.4.3
wp plugin list --name=shortcodes-ultimate --fields=name,status,version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.