CVE-2025-7653 Overview
The EPay.bg Payments plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability in its epay shortcode. The flaw affects all versions up to and including 0.1. Authenticated users with contributor-level access or higher can inject arbitrary JavaScript through unsanitized shortcode attributes. The injected scripts execute in the browser of any visitor who loads the affected page. The vulnerability is classified under [CWE-79] and stems from insufficient input sanitization and output escaping.
Critical Impact
Contributor-level accounts can persist arbitrary JavaScript in published pages, enabling session theft, redirect chains, and administrative account takeover when higher-privileged users view the injected content.
Affected Products
- WordPress EPay.bg Payments plugin, all versions through 0.1
- WordPress sites permitting contributor-level or higher registration
- Any site rendering the [epay] shortcode with attacker-controlled attributes
Discovery Timeline
- 2025-07-19 - CVE-2025-7653 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-7653
Vulnerability Analysis
The EPay.bg Payments plugin registers an epay shortcode that renders payment button markup based on attributes supplied by the page author. The shortcode handler in epay-payments.php incorporates user-supplied attribute values directly into HTML output without applying WordPress escaping helpers such as esc_attr() or esc_html(). When a contributor embeds the shortcode with a crafted attribute value containing HTML or JavaScript payloads, the plugin emits the payload verbatim into the rendered page.
The stored nature of the flaw amplifies its impact. Once a contributor submits a page containing the malicious shortcode and an editor or administrator publishes or previews it, the payload executes in that reviewer's browser session. Exploitation requires only contributor-level credentials, a role commonly granted to guest authors and low-trust accounts.
Root Cause
The root cause is missing input sanitization on shortcode attributes and missing output escaping when those attributes are echoed into HTML. WordPress provides sanitize_text_field(), esc_attr(), and wp_kses() for these purposes, none of which the vulnerable release invokes on the affected attributes.
Attack Vector
An authenticated contributor submits a post or page containing an [epay] shortcode with a crafted attribute value that closes the surrounding HTML context and injects a <script> block or event handler. When an authenticated user with higher privileges views the page, the browser executes the payload under the site's origin, enabling cookie theft, forced administrative actions via the REST API, or persistent backdoor creation.
See the Wordfence Vulnerability Analysis and the plugin source for the vulnerable handler.
Detection Methods for CVE-2025-7653
Indicators of Compromise
- Post or page content containing [epay ...] shortcodes with attribute values that include <, >, script, onerror, onload, or javascript: substrings
- Unexpected outbound requests from administrator sessions to third-party domains shortly after previewing contributor-submitted content
- New administrator accounts or modified user roles created immediately after an editor viewed a page authored by a contributor
Detection Strategies
- Query the wp_posts table for post_content values matching regex patterns that combine [epay with HTML or JavaScript syntax
- Enable WordPress audit logging to correlate contributor-submitted content with subsequent privileged actions
- Deploy a web application firewall rule that inspects shortcode attribute values for HTML control characters
Monitoring Recommendations
- Alert on newly registered contributor accounts followed by shortcode-heavy post submissions
- Monitor browser console errors and Content Security Policy (CSP) violation reports from /wp-admin/ pages
- Track plugin inventory changes and flag installations of epaybg-payments at version 0.1 or earlier
How to Mitigate CVE-2025-7653
Immediate Actions Required
- Deactivate and remove the EPay.bg Payments plugin until a patched release is verified
- Audit existing posts and pages for [epay] shortcodes containing suspicious attribute values and purge malicious entries
- Rotate credentials for administrator and editor accounts that may have previewed injected pages
Patch Information
No fixed version is listed in the enriched CVE data at the time of publication. Consult the Wordfence advisory for updates on a vendor patch. Until a fixed release is available, treat the plugin as unmaintained.
Workarounds
- Restrict the contributor role or remove the edit_posts capability from untrusted accounts
- Enforce a strict Content Security Policy that disallows inline scripts on public pages
- Apply a WAF signature that blocks shortcode attributes containing <script, onerror=, or javascript: payloads
# Configuration example: remove the vulnerable plugin via WP-CLI
wp plugin deactivate epaybg-payments
wp plugin delete epaybg-payments
# Search for potentially injected shortcodes
wp db query "SELECT ID, post_title FROM wp_posts WHERE post_content REGEXP '\\[epay[^]]*(<|script|onerror|onload|javascript:)'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
