CVE-2025-7658 Overview
The Temporarily Hidden Content plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability in the temphc-start shortcode. The flaw affects all versions up to and including 1.0.6. It stems from insufficient input sanitization and output escaping on user-supplied shortcode attributes.
Authenticated attackers with contributor-level access or above can inject arbitrary web scripts into pages. The injected scripts execute in the browser of any user who visits the affected page, including administrators. The vulnerability is classified as [CWE-79]: Improper Neutralization of Input During Web Page Generation.
Critical Impact
Contributor-level users can inject persistent JavaScript that executes against site visitors and administrators, enabling session theft, forced administrative actions, and account takeover.
Affected Products
- WordPress Temporarily Hidden Content plugin versions 1.0.0 through 1.0.6
- WordPress sites permitting contributor-or-higher user registration
- Any deployment using the temphc-start shortcode
Discovery Timeline
- 2025-07-19 - CVE-2025-7658 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-7658
Vulnerability Analysis
The Temporarily Hidden Content plugin provides a shortcode named temphc-start that renders content based on user-defined attributes. The plugin logic passes these shortcode attributes into the output HTML without sanitizing input or escaping output. Any string supplied by a post author is echoed directly into the rendered page.
Stored XSS differs from reflected XSS because the payload persists in the database. Every subsequent visitor triggers execution without requiring a crafted URL. Because WordPress permits contributors to create posts containing shortcodes, the barrier to exploitation is low on sites that accept community contributions.
The scope change indicated in the vulnerability data reflects that scripts executing in a victim's browser can act beyond the plugin boundary, reaching administrative interfaces available to the logged-in user.
Root Cause
The root cause is missing input sanitization and missing output escaping in the plugin's public rendering class. Shortcode attribute values from class-temporarily-hidden-content-public.php flow into the countdown_view.tpl template without passing through esc_attr(), esc_html(), or wp_kses(). WordPress provides these functions specifically to neutralize HTML control characters in dynamic output.
Attack Vector
An attacker with contributor privileges creates or edits a post containing the temphc-start shortcode. The attacker supplies a shortcode attribute value containing JavaScript, such as an event handler or <script> tag. When the post is previewed, published, or viewed, the malicious script executes in the visitor's browser context. Administrators reviewing pending contributor submissions are prime targets for privilege escalation through forced account creation or plugin installation.
The vulnerability mechanism is documented in the Wordfence Vulnerability Report and the WordPress Plugin Code File. No verified exploit code is publicly available at this time.
Detection Methods for CVE-2025-7658
Indicators of Compromise
- Posts or pages containing temphc-start shortcode attributes with HTML tags, event handlers (onerror, onload, onclick), or javascript: URIs.
- Unexpected outbound requests from browsers loading WordPress pages that reference the plugin.
- Newly created administrator accounts or altered user roles following contributor post submissions.
- Modified plugin or theme files timestamped shortly after a contributor-authored post was viewed by an administrator.
Detection Strategies
- Search the wp_posts table for temphc-start shortcode invocations and inspect attribute values for HTML control characters.
- Deploy a web application firewall rule to block requests posting shortcode content containing <script>, onerror=, or similar payloads.
- Monitor WordPress audit logs for contributor role users creating or editing posts that contain shortcodes.
Monitoring Recommendations
- Enable a WordPress activity logging plugin to record post creation, editing, and role changes with actor attribution.
- Alert on administrator sessions that trigger unusual admin-ajax.php or REST API calls immediately after viewing contributor content.
- Track installation of the Temporarily Hidden Content plugin across managed WordPress sites and inventory versions against 1.0.6.
How to Mitigate CVE-2025-7658
Immediate Actions Required
- Update the Temporarily Hidden Content plugin to a version above 1.0.6 once released, or deactivate and remove the plugin.
- Audit existing posts and pages for the temphc-start shortcode and remove any suspicious attribute values.
- Review contributor and author accounts and revoke access for untrusted users pending remediation.
- Rotate administrator session cookies and passwords if malicious shortcode content was rendered.
Patch Information
As of the latest NVD update, all versions up to and including 1.0.6 are affected. Site administrators should monitor the WordPress plugin repository for a patched release and apply updates immediately upon availability. Where no patch is available, uninstall the plugin.
Workarounds
- Restrict the temphc-start shortcode by unregistering it in a custom mu-plugin using remove_shortcode('temphc-start').
- Downgrade contributor accounts to subscriber level until a fix is deployed.
- Enforce a Content Security Policy that disallows inline scripts and untrusted script sources on WordPress front-end pages.
- Require editorial review of all contributor posts before publication and inspect raw post content for shortcode attributes.
# Configuration example: disable the vulnerable shortcode via WP-CLI
wp eval "remove_shortcode('temphc-start');"
# Search all posts for the vulnerable shortcode
wp db query "SELECT ID, post_title, post_author FROM wp_posts WHERE post_content LIKE '%temphc-start%';"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.