CVE-2025-7661 Overview
CVE-2025-7661 is a Stored Cross-Site Scripting (XSS) vulnerability in the Partnerský systém Martinus plugin for WordPress. The flaw affects all versions up to and including 1.7.1. The vulnerability exists in the plugin's martinus shortcode, which fails to sanitize user-supplied attributes and does not escape output correctly. Authenticated users with contributor-level access or higher can inject arbitrary JavaScript into pages. The injected scripts execute in the browser of any visitor who views the affected page. The issue is categorized under CWE-79.
Critical Impact
Authenticated contributors can persist arbitrary JavaScript in WordPress pages, enabling session theft, credential harvesting, and administrative account takeover when higher-privileged users view the injected content.
Affected Products
- Partnerský systém Martinus WordPress plugin — all versions up to and including 1.7.1
- WordPress sites permitting contributor-level or higher account registration
- WordPress installations using the martinus shortcode in published content
Discovery Timeline
- 2025-07-19 - CVE-2025-7661 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-7661
Vulnerability Analysis
The vulnerability resides in the martinus shortcode handler defined in martinus-pp.php. The plugin accepts user-controlled shortcode attributes and renders them into page output without applying WordPress sanitization functions such as esc_attr() or esc_html(). An authenticated attacker with contributor privileges can embed the shortcode with malicious attribute values inside post or page content. When any visitor loads the rendered page, the injected script executes in their browser session under the site's origin.
The attack scope extends beyond the vulnerable component. Payloads executed in an administrator's browser can create new admin accounts, modify plugin settings, or exfiltrate authenticated session cookies. Because the payload is stored server-side, exploitation requires no additional interaction from the attacker after injection. Contributor-level access is a low bar on many WordPress sites that accept guest authors or use open registration for content submission.
Root Cause
The root cause is insufficient input sanitization and missing output escaping on user-supplied shortcode attributes. The plugin does not filter attribute values through WordPress-provided escaping APIs before echoing them into the HTML response. See the WordPress Plugin Source Code for the affected code path.
Attack Vector
The attack requires network access to the WordPress site and an authenticated account with contributor-level privileges or above. The attacker creates or edits a post containing the martinus shortcode with attribute values that break out of the intended HTML context and inject a <script> payload. Once the post is viewable, any authenticated or unauthenticated visitor who loads the page triggers script execution. Details of the exploitation path are documented in the Wordfence Vulnerability Report.
Detection Methods for CVE-2025-7661
Indicators of Compromise
- Post or page content containing [martinus ...] shortcodes with attribute values that include HTML tags, JavaScript event handlers, or javascript: URIs.
- Unexpected outbound requests from user browsers to attacker-controlled domains originating from pages that render the martinus shortcode.
- New WordPress administrator accounts or role changes created shortly after contributors publish content containing the plugin's shortcode.
Detection Strategies
- Audit the wp_posts table for shortcode usage matching patterns such as [martinus combined with <script, onerror=, or onload=.
- Monitor WordPress audit logs for contributor-authored posts that reference the vulnerable plugin's shortcode.
- Review web server access logs for anomalous requests to pages containing the martinus shortcode with suspicious referrers or geographic distribution.
Monitoring Recommendations
- Enable file integrity monitoring on the wp-content/plugins/martinus-partnersky-system/ directory to detect tampering.
- Deploy Content Security Policy (CSP) headers and alert on script-src violations reported by browsers.
- Track privilege changes, plugin installations, and admin account creation events in a centralized log collector for correlation.
How to Mitigate CVE-2025-7661
Immediate Actions Required
- Deactivate the Partnerský systém Martinus plugin until a patched release is available.
- Restrict contributor-level and higher account creation, and audit existing accounts for legitimacy.
- Scan existing posts and pages for the martinus shortcode and remove any entries containing HTML or script payloads in attributes.
Patch Information
As of the last NVD update on 2026-06-17, no fixed version is identified beyond 1.7.1. Consult the Wordfence Vulnerability Report for the latest patch status and apply the vendor-supplied update as soon as it becomes available.
Workarounds
- Remove the plugin from the WordPress installation if the affiliate functionality is not business-critical.
- Apply a Web Application Firewall (WAF) rule that blocks POST requests containing [martinus alongside <script, onerror, or onload tokens.
- Downgrade contributor accounts or require editor review before publication so shortcode-bearing posts cannot go live without inspection.
# Configuration example: disable the plugin via WP-CLI
wp plugin deactivate martinus-partnersky-system
wp plugin delete martinus-partnersky-system
# Search for posts containing the vulnerable shortcode
wp db query "SELECT ID, post_title FROM wp_posts WHERE post_content LIKE '%[martinus%';"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
