CVE-2025-8064 Overview
CVE-2025-8064 is a stored Cross-Site Scripting (XSS) vulnerability in the Bible SuperSearch plugin for WordPress. The flaw affects all versions up to and including 6.0.1. The plugin fails to sanitize input and escape output for the selector_height shortcode parameter. Authenticated users with Contributor-level access or higher can inject arbitrary JavaScript into pages. The injected script executes in the browser of any visitor who accesses the affected page. The issue is tracked under CWE-79 and was analyzed by the Wordfence Threat Intelligence team.
Critical Impact
Authenticated Contributors can persist JavaScript payloads in WordPress pages, enabling session theft, admin account takeover, and drive-by redirection of site visitors.
Affected Products
- Bible SuperSearch WordPress plugin, all versions through 6.0.1
- WordPress sites permitting Contributor-level (or higher) registration
- Sites embedding the vulnerable Bible SuperSearch shortcode with the selector_height attribute
Discovery Timeline
- 2025-08-21 - CVE-2025-8064 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-8064
Vulnerability Analysis
The vulnerability resides in the shortcode handler defined in wp/class.shortcodes.php. The handler accepts user-supplied shortcode attributes and interpolates them directly into HTML markup. The selector_height attribute is written into an inline style value without escaping. An authenticated Contributor can craft shortcode input that breaks out of the style attribute and injects executable HTML or JavaScript. Because shortcodes are rendered when the page is viewed, the payload becomes stored XSS. Any subsequent visitor, including administrators, will execute the attacker-controlled script in their browser session.
Root Cause
The plugin lacked input sanitization and output escaping when rendering shortcode attributes into HTML. Specifically, selector_height and sel_color values were placed directly inside inline style blocks without calling WordPress escaping helpers such as esc_attr().
Attack Vector
Exploitation requires an authenticated account with Contributor privileges or higher on a WordPress site running the vulnerable plugin. The attacker publishes or edits a page containing the Bible SuperSearch shortcode with a malicious selector_height value. When the page renders, the injected script executes in the browser of every visitor, including administrators viewing the content in the dashboard preview.
// Patched code in wp/class.shortcodes.php
), $atts );
// static::_validateAttributes($a);
$a['selector_height'] = esc_attr($a['selector_height']);
$a['sel_color'] = esc_attr($a['sel_color']);
$html = '';
$html .= "<div style='height: {$a['selector_height']}; overflow-y:auto'>";
$html .= "<table><tr><th>Name</th><th>ID</th><th>Select</th></tr>";
foreach($interfaces as $id => $int) {
$selected = ($id == $sel_interface) ? TRUE : FALSE;
// Source: https://github.com/aicwebtech/Bible-SuperSearch-WordPress-Plugin/commit/535e1a48a6d6135020209adfd9881a0c1878b741
The patch wraps both attributes with esc_attr() before they are interpolated into the inline style, preventing quote-breakout injection.
Detection Methods for CVE-2025-8064
Indicators of Compromise
- Pages or posts containing Bible SuperSearch shortcodes with unusual characters in the selector_height attribute, such as quotes, angle brackets, or on* event handler names.
- Unexpected <script> tags, inline event handlers, or external script src URLs rendered inside plugin-generated <div> containers.
- New Contributor or Author accounts creating content that embeds the plugin's shortcodes shortly after registration.
Detection Strategies
- Query the wp_posts table for post_content values that reference the Bible SuperSearch shortcode combined with suspicious tokens (<script, javascript:, onerror=, onload=).
- Deploy a WordPress security plugin or Web Application Firewall (WAF) rule that inspects shortcode attribute values for HTML control characters.
- Review web server access logs for administrator sessions that trigger outbound requests to unknown domains immediately after rendering plugin-driven pages.
Monitoring Recommendations
- Alert on edits to published pages by non-Editor accounts, particularly when the diff introduces shortcode attribute changes.
- Monitor browser Content Security Policy (CSP) violation reports for inline script or style violations originating from plugin-rendered containers.
- Track plugin version inventory across managed WordPress sites and flag any instance still running Bible SuperSearch 6.0.1 or earlier.
How to Mitigate CVE-2025-8064
Immediate Actions Required
- Update the Bible SuperSearch plugin to the fixed release identified in WordPress changeset 3345278.
- Audit all pages using the plugin's shortcodes and remove any content containing unexpected HTML in the selector_height or sel_color attributes.
- Rotate credentials for administrator accounts that may have viewed compromised pages and invalidate active WordPress sessions.
Patch Information
The vendor addressed the issue by applying esc_attr() to the selector_height and sel_color shortcode attributes in wp/class.shortcodes.php. The fix is included in the release published via WordPress changeset 3345278 and the upstream GitHub commit 535e1a4. Site owners should upgrade to the version referenced on the official plugin page.
Workarounds
- Deactivate the Bible SuperSearch plugin until the patched version is deployed on all sites.
- Restrict the ability to publish or edit posts to trusted Editor and Administrator roles, removing Contributor-level publishing privileges.
- Enforce a strict Content Security Policy that blocks inline scripts and disallows untrusted script sources on public pages.
# Verify installed plugin version via WP-CLI and update
wp plugin get biblesupersearch --field=version
wp plugin update biblesupersearch
wp plugin list --status=active | grep biblesupersearch
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
