Skip to main content

CVE-2025-7959: Station Pro WordPress Plugin XSS Vulnerability

CVE-2025-7959 is a stored XSS flaw in the Station Pro WordPress plugin that allows authenticated attackers to inject malicious scripts. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2025-7959 Overview

The Station Pro plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability [CWE-79] in the width and height parameters. The flaw affects all versions up to and including 2.4.2. Insufficient input sanitization and output escaping in the plugin's player component allow authenticated users with Contributor-level access or above to inject arbitrary web scripts. Injected scripts execute in the browser of any user who views the affected page.

Critical Impact

Authenticated contributors can persist JavaScript payloads into WordPress pages, enabling session theft, administrative account takeover, and drive-by redirection of site visitors.

Affected Products

  • WordPress Station Pro plugin versions <= 2.4.2
  • WordPress sites permitting Contributor-level or higher registration
  • Any WordPress deployment embedding the Station Pro player shortcode

Discovery Timeline

  • 2025-07-24 - CVE-2025-7959 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-7959

Vulnerability Analysis

The vulnerability resides in the Station Pro player rendering logic located in core/inc/player/class-station-player.php. The plugin accepts width and height attributes from shortcode input and writes them directly into HTML output without sanitization or escaping. An authenticated attacker with at least Contributor privileges can supply attribute values that break out of the enclosing HTML context and inject arbitrary script tags or event handlers.

Because the payload is stored within post content, the injected script executes for every visitor rendering the page. Attackers can hijack administrator sessions, perform actions on behalf of authenticated users, or pivot to site-wide compromise through plugin or theme editing capabilities. The stored nature of the flaw makes it particularly dangerous on multi-author sites.

Root Cause

The plugin fails to apply WordPress sanitization functions such as absint(), sanitize_text_field(), or esc_attr() to the width and height shortcode parameters before emitting them into HTML. This omission violates the WordPress plugin security guidance that mandates escaping all user-controlled output.

Attack Vector

Exploitation requires an authenticated account with Contributor-level access or higher. The attacker inserts a crafted Station Pro shortcode into a post or page, supplying malicious content in the width or height attribute. When an editor, administrator, or site visitor loads the page, the injected script executes in their browser under the site's origin. See the Wordfence Vulnerability Report and the WordPress Plugin Source Code for technical details.

Detection Methods for CVE-2025-7959

Indicators of Compromise

  • Post or page content containing Station Pro shortcodes with non-numeric values in the width or height attributes
  • Rendered HTML containing <script> tags or on* event handlers inside player wrapper elements
  • Unexpected outbound requests from administrator browsers to attacker-controlled domains after viewing plugin-rendered pages

Detection Strategies

  • Audit the wp_posts table for stored shortcodes containing characters such as ", <, or javascript: within Station Pro attributes
  • Review recent contributor and author submissions for pages using the plugin's player shortcode
  • Inspect web server access logs for POST requests to post.php or post-new.php from low-privilege accounts creating pages that embed the plugin

Monitoring Recommendations

  • Enable WordPress activity logging to capture post revisions authored by Contributor and Author roles
  • Deploy a web application firewall rule that flags shortcode attributes containing HTML control characters
  • Monitor administrator sessions for anomalous API calls that could indicate XSS-driven account abuse

How to Mitigate CVE-2025-7959

Immediate Actions Required

  • Update the Station Pro plugin to a version above 2.4.2 once the vendor publishes a fix
  • Temporarily deactivate the Station Pro plugin on sites that permit untrusted contributor registrations
  • Review all existing pages using the Station Pro shortcode and remove suspicious width or height attribute values
  • Rotate credentials for any administrator account that viewed potentially compromised pages

Patch Information

As of the last NVD update on 2026-06-17, no fixed version is referenced in the advisory. Site operators should consult the WordPress Plugin Developer Info page for release updates and apply the patched version as soon as it becomes available.

Workarounds

  • Restrict content creation to trusted Editor and Administrator roles until a patched release is installed
  • Disable Contributor registrations and remove existing accounts that are not required
  • Apply a WAF signature that blocks HTML metacharacters within Station Pro shortcode attributes
  • Use a Content Security Policy that restricts inline script execution to reduce the impact of stored XSS payloads

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.