Skip to main content

CVE-2025-7655: Live Stream Badger WordPress XSS Vulnerability

CVE-2025-7655 is a stored XSS vulnerability in the Live Stream Badger WordPress plugin affecting versions up to 1.4.3. Authenticated attackers can inject malicious scripts via shortcode attributes. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2025-7655 Overview

The Live Stream Badger plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability in its livestream shortcode. The flaw affects all versions up to and including 1.4.3. Insufficient input sanitization and output escaping on user-supplied shortcode attributes allow authenticated attackers with contributor-level access or higher to inject arbitrary web scripts. Injected scripts execute whenever any user visits a page containing the malicious shortcode. The vulnerability is classified as [CWE-79] Improper Neutralization of Input During Web Page Generation.

Critical Impact

Authenticated contributors can persist arbitrary JavaScript into WordPress pages, enabling session theft, administrative account takeover, and drive-by attacks against site visitors.

Affected Products

  • WordPress Live Stream Badger plugin versions up to and including 1.4.3
  • WordPress sites permitting contributor-level user registration
  • Multi-author WordPress deployments using the livestream shortcode

Discovery Timeline

  • 2025-07-19 - CVE-2025-7655 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-7655

Vulnerability Analysis

The Live Stream Badger plugin registers a livestream shortcode that renders embedded stream players inside WordPress posts and pages. The shortcode accepts user-supplied attributes that are later reflected into rendered HTML output. The plugin fails to sanitize these attributes on input and does not escape them on output.

Contributors in WordPress can author posts containing shortcodes but cannot publish them without editor review. Attackers abuse this workflow by inserting a malicious livestream shortcode into draft content. Once an editor previews or publishes the draft, the payload executes in the reviewer's browser under the site's origin.

The scope change from cross-site scripting causes the injected script to execute in the context of any authenticated administrator who views the affected page. This enables cookie theft, forced administrative actions via authenticated requests, and persistent backdoor installation through plugin or theme modification.

Root Cause

The root cause is missing input validation and output encoding in the shortcode handler implemented in class-embedded-stream.php and the corresponding view class class-embedded-twitch-view.php. Attribute values passed to the shortcode are concatenated directly into HTML markup without calls to WordPress sanitization helpers such as esc_attr(), esc_html(), or wp_kses().

Attack Vector

An attacker with contributor-level credentials submits a post containing a crafted livestream shortcode. Attributes carry HTML or JavaScript payloads that break out of the intended attribute context. When any visitor renders the page, the browser executes the injected script under the WordPress site origin.

The vulnerability requires authentication but no user interaction beyond viewing the affected page. For technical details on the vulnerable code paths, refer to the Wordfence Vulnerability Analysis and the plugin source at the WordPress Live Stream Badger Class.

Detection Methods for CVE-2025-7655

Indicators of Compromise

  • Posts or pages containing [livestream] shortcodes with attributes carrying angle brackets, javascript: URIs, or event handlers such as onerror and onload
  • Newly created contributor accounts followed by draft submissions containing shortcodes
  • Unexpected outbound requests from browsers of authenticated administrators to attacker-controlled domains
  • Modifications to wp_options, wp_users, or plugin files following administrator visits to contributor drafts

Detection Strategies

  • Audit the wp_posts table for livestream shortcode instances and inspect attribute values for HTML metacharacters
  • Deploy web application firewall rules that inspect POST bodies to /wp-admin/post.php for shortcode attributes containing script payloads
  • Monitor WordPress audit logs for post submissions by contributor-role accounts
  • Correlate contributor account creation with subsequent draft submissions containing embed shortcodes

Monitoring Recommendations

  • Enable Content Security Policy (CSP) reporting to surface unexpected script execution on WordPress pages
  • Log and alert on administrator session activity that follows viewing a contributor-authored draft
  • Track plugin version inventory across WordPress deployments and flag installations of Live Stream Badger at version 1.4.3 or earlier
  • Ingest WordPress access and error logs into a centralized platform to enable cross-site correlation of shortcode abuse

How to Mitigate CVE-2025-7655

Immediate Actions Required

  • Deactivate the Live Stream Badger plugin on all WordPress sites until a patched version is installed
  • Audit existing posts and drafts for malicious livestream shortcode content and remove affected entries
  • Rotate credentials and session tokens for any administrator who reviewed contributor drafts containing the shortcode
  • Restrict new contributor registrations until the plugin is patched or replaced

Patch Information

As of the last NVD update on 2026-06-17, no fixed version beyond 1.4.3 is referenced in the advisory. Site operators should monitor the Wordfence Vulnerability Analysis entry for updated remediation guidance and install any subsequent plugin release that addresses the sanitization gap.

Workarounds

  • Remove the Live Stream Badger plugin entirely and use an alternative embed solution with active maintenance
  • Restrict shortcode usage by removing the contributor role or elevating publishing permissions to trusted users only
  • Deploy a WordPress security plugin ruleset that blocks shortcode attributes containing <script>, javascript:, or event handler patterns
  • Enforce a strict Content Security Policy that disallows inline script execution site-wide
bash
# Disable the vulnerable plugin via WP-CLI
wp plugin deactivate live-stream-badger --all
wp plugin delete live-stream-badger

# Audit posts for the vulnerable shortcode
wp db query "SELECT ID, post_title, post_status, post_author \
  FROM wp_posts \
  WHERE post_content LIKE '%[livestream%';"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.