Skip to main content

CVE-2025-7810: StreamWeasels Kick Integration XSS Flaw

CVE-2025-7810 is a stored cross-site scripting vulnerability in the StreamWeasels Kick Integration WordPress plugin that lets authenticated attackers inject malicious scripts. This article covers technical details, affected versions, impact, and mitigation strategies.

Published:

CVE-2025-7810 Overview

The StreamWeasels Kick Integration plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 1.1.4. The flaw resides in the plugin's data-uuid attribute handling, where insufficient input sanitization and output escaping allow authenticated attackers with contributor-level access or above to inject arbitrary web scripts. Injected scripts execute in the browser of any user who visits an affected page. The issue is tracked under CWE-79 and was disclosed through the Wordfence Vulnerability Report.

Critical Impact

Authenticated contributors can persist malicious JavaScript in WordPress pages, enabling session theft, credential harvesting, and privileged action hijacking against administrators who view the injected content.

Affected Products

  • StreamWeasels Kick Integration plugin for WordPress, versions up to and including 1.1.4
  • WordPress sites permitting contributor-level accounts or higher to use the plugin's shortcodes
  • Any page rendering plugin output through the vulnerable public-facing JavaScript at streamweasels-kick-public.js

Discovery Timeline

  • 2025-07-29 - CVE-2025-7810 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-7810

Vulnerability Analysis

The vulnerability is a stored Cross-Site Scripting flaw in the StreamWeasels Kick Integration plugin. Attackers with contributor privileges submit shortcode attributes that flow into the data-uuid attribute rendered by the plugin's public JavaScript. Because the plugin fails to sanitize input on save and does not escape output on render, attacker-controlled markup is written into the DOM verbatim. When any visitor loads the affected page, the injected script executes under the site's origin.

Stored XSS in a WordPress context is impactful because payloads persist across sessions and target higher-privileged users. An administrator viewing an injected post can trigger requests that create new admin accounts, install plugins, or exfiltrate nonces. The requirement for contributor-level access lowers the attacker skill bar on sites that accept guest authors or open registration.

Root Cause

The plugin accepts user-supplied values for the data-uuid shortcode attribute and passes them into HTML output without applying WordPress escaping functions such as esc_attr() or sanitize_text_field(). Client-side rendering logic in streamweasels-kick-public.js (see the vulnerable source line) further processes the attribute without contextual encoding. The fix landed in WordPress Changeset #3335307.

Attack Vector

An authenticated attacker with contributor privileges creates or edits a post containing the plugin's shortcode with a crafted data-uuid value that breaks out of the attribute context. The payload is stored in the WordPress database. When a visitor or administrator loads the page, the browser parses the injected markup and executes the attacker's JavaScript in the site's origin. User interaction is required — a victim must load the page — and the scope change reflects script execution beyond the plugin's boundary into the hosting document.

No verified public proof-of-concept code is available. See the Wordfence advisory for additional technical context.

Detection Methods for CVE-2025-7810

Indicators of Compromise

  • Post or page content containing shortcode attributes with unusual data-uuid values that include angle brackets, quotes, javascript: URIs, or on* event handlers
  • Unexpected <script> tags or inline event handlers rendered within plugin-generated markup on public pages
  • New administrator accounts, plugin installs, or option changes shortly after a contributor-authored post was viewed by an admin

Detection Strategies

  • Query the wp_posts table for post content matching the plugin's shortcode with suspicious characters in the data-uuid attribute
  • Review web server logs for requests to pages authored by contributors that correlate with outbound requests to unfamiliar domains
  • Monitor browser Content Security Policy (CSP) violation reports for inline script executions on pages using the plugin

Monitoring Recommendations

  • Alert on modifications to posts by contributor-role accounts that include HTML control characters within shortcode attributes
  • Track privileged administrative actions initiated immediately after loading contributor-authored content
  • Log and review plugin version data across WordPress deployments to confirm all instances of StreamWeasels Kick Integration are above 1.1.4

How to Mitigate CVE-2025-7810

Immediate Actions Required

  • Update the StreamWeasels Kick Integration plugin to the version that includes Changeset #3335307, which addresses the sanitization gap
  • Audit all existing posts and pages for shortcode invocations containing suspicious data-uuid values and remove or neutralize any injected payloads
  • Review user roles and revoke contributor access for accounts that are no longer needed or are unverified

Patch Information

The vendor addressed the issue in a release following version 1.1.4. The fix commit is documented in WordPress Changeset #3335307 and adds proper sanitization and output escaping to the data-uuid handling path. Site operators should apply the update through the WordPress plugin management interface or WP-CLI.

Workarounds

  • Deactivate the StreamWeasels Kick Integration plugin until the patched version can be deployed
  • Restrict shortcode usage by limiting which roles may publish content containing the plugin's shortcodes through a role management plugin
  • Deploy a Web Application Firewall (WAF) rule that inspects post content for HTML-breaking characters within the plugin's data-uuid attribute
  • Enforce a strict Content Security Policy that disallows inline script execution on pages rendered by the plugin

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.