CVE-2025-7649 Overview
CVE-2025-7649 is a Stored Cross-Site Scripting (XSS) vulnerability in the Surbma | Recent Comments Shortcode plugin for WordPress. The flaw affects all versions up to and including 2.0. The plugin fails to properly sanitize input and escape output for user-supplied attributes passed to its recent-comments shortcode. Authenticated users with contributor-level access or above can inject arbitrary JavaScript into pages. The malicious script executes in the browser of any visitor who loads the affected page. The vulnerability is tracked under CWE-79: Improper Neutralization of Input During Web Page Generation.
Critical Impact
Authenticated contributors can persist arbitrary JavaScript that runs in the context of site visitors, enabling session theft, redirection, and administrative account takeover through follow-on attacks.
Affected Products
- Surbma | Recent Comments Shortcode plugin for WordPress — all versions through 2.0
- WordPress sites permitting contributor-level or higher registrations
- Any WordPress installation rendering pages that embed the recent-comments shortcode
Discovery Timeline
- 2025-08-16 - CVE-2025-7649 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-7649
Vulnerability Analysis
The vulnerability resides in the shortcode handler registered by the plugin for [recent-comments]. The handler accepts user-supplied attributes and renders them into the page output without applying proper sanitization or escaping. WordPress shortcodes can be embedded by users with edit_posts capability, which includes the contributor role. Because contributor content flows through the same shortcode expansion path as higher-privileged content, injected attribute values persist in the database and are rendered whenever the page is served.
The stored nature of the flaw means a single successful injection affects every subsequent visitor to the compromised page. Script execution occurs in the browser context of the visitor, including administrators previewing pending submissions.
Root Cause
The root cause is missing input sanitization on incoming shortcode attributes and missing output escaping when those attributes are echoed into HTML. WordPress provides helper functions such as sanitize_text_field(), esc_attr(), and esc_html() that the plugin does not apply to attribute values before rendering. See the plugin source at tag 2.0 for the vulnerable handler.
Attack Vector
An attacker registers or compromises a contributor account. They then create a draft post containing the recent-comments shortcode with an attribute value carrying a JavaScript payload. When an administrator previews the submission or the page is published and served to visitors, the browser executes the payload. See the Wordfence advisory for additional exploitation context.
// No verified public proof-of-concept code is available.
// Refer to the Wordfence advisory linked above for exploitation details.
Detection Methods for CVE-2025-7649
Indicators of Compromise
- Post or page content in wp_posts containing [recent-comments shortcode invocations with attribute values that include <script>, onerror=, onload=, or javascript: strings.
- Unexpected outbound requests from visitor browsers to attacker-controlled domains after loading pages that embed the shortcode.
- Newly created contributor accounts followed by draft submissions containing the vulnerable shortcode.
Detection Strategies
- Audit the WordPress database for shortcode attributes containing HTML tags or event handlers using SQL queries against post_content.
- Enable a web application firewall in monitoring mode to log requests that submit shortcode content with script-like patterns.
- Review user registration and role-change logs for recent contributor-level accounts and correlate with post creation activity.
Monitoring Recommendations
- Track the wp_insert_post and save_post hooks for content submitted by contributor roles that includes shortcode payloads with suspicious characters.
- Monitor administrator sessions for anomalous requests triggered while previewing pending posts.
- Alert on modifications to plugin files under wp-content/plugins/surbma-recent-comments-shortcode/.
How to Mitigate CVE-2025-7649
Immediate Actions Required
- Deactivate the Surbma | Recent Comments Shortcode plugin until a fixed version is confirmed installed.
- Audit existing posts and pages for any use of the [recent-comments] shortcode and inspect attribute values for injected script content.
- Restrict contributor and author registrations, and review recently created low-privilege accounts.
Patch Information
At the time of publication, no fixed version beyond 2.0 is referenced in the available advisories. Monitor the WordPress plugin repository and the Wordfence advisory for an updated release, and apply it as soon as available.
Workarounds
- Remove all instances of the [recent-comments] shortcode from published content until the plugin is patched.
- Deploy a WordPress-aware WAF rule that blocks shortcode attribute values containing HTML tags, event handlers, or javascript: URIs.
- Reduce the trust boundary by limiting contributor role assignments and requiring editor approval for all draft previews on isolated staging environments.
# Locate posts using the vulnerable shortcode via WP-CLI
wp db query "SELECT ID, post_title, post_status FROM wp_posts \
WHERE post_content LIKE '%[recent-comments%' \
AND post_status IN ('publish','pending','draft');"
# Disable the plugin site-wide until a patch is verified
wp plugin deactivate surbma-recent-comments-shortcode
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
