CVE-2025-8313 Overview
CVE-2025-8313 is a Stored Cross-Site Scripting (XSS) vulnerability [CWE-79] affecting the Campus Directory plugin for WordPress. The flaw exists in all versions up to and including 1.9.1. The noaccess_msg parameter fails to properly sanitize input and escape output, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary JavaScript. Injected scripts execute in the browser of any user who visits an affected page, enabling session theft, account takeover, or redirection to attacker-controlled infrastructure.
Critical Impact
Authenticated Contributor-level users can inject persistent JavaScript that executes against site visitors, including administrators, when they view affected pages.
Affected Products
- WordPress Campus Directory plugin versions ≤ 1.9.1
- Sites permitting Contributor-level or higher account registration
- WordPress installations using the emd-form-builder-lite component bundled with Campus Directory
Discovery Timeline
- 2025-08-05 - CVE-2025-8313 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in the NVD database
Technical Details for CVE-2025-8313
Vulnerability Analysis
The vulnerability resides in the Campus Directory plugin's form builder component, specifically in the handling of the noaccess_msg parameter within includes/emd-form-builder-lite/emd-form-frontend.php. The plugin accepts user-supplied content for this parameter without applying sufficient sanitization on input or escaping on output.
Contributor-level accounts can supply crafted values containing HTML and JavaScript. The plugin stores those values and later renders them into pages served to other users. When a visitor loads the affected page, the injected payload executes in that visitor's browser under the origin of the WordPress site.
Because the payload runs in the context of the site, an attacker can steal session cookies, exfiltrate CSRF tokens, perform actions on behalf of the victim, or pivot toward administrator account compromise if a privileged user views the content.
Root Cause
The underlying defect is missing input validation combined with missing output escaping on the noaccess_msg parameter. WordPress provides functions such as wp_kses_post() and esc_html() for these purposes, but the vulnerable code path renders the stored value directly into the response HTML.
Attack Vector
Exploitation requires network access and an authenticated Contributor-level account. No user interaction is needed beyond a victim loading an affected page. Because the scope changes to include another security authority (the visitor's session), the vulnerability produces confidentiality and integrity impact on victims beyond the attacker's own privilege boundary.
A full technical write-up is available in the Wordfence Vulnerability Analysis, and the vulnerable source file is visible in the WordPress Plugin Frontend PHP source.
Detection Methods for CVE-2025-8313
Indicators of Compromise
- Presence of <script>, onerror=, onload=, or javascript: strings in stored noaccess_msg values within the WordPress database
- Unexpected outbound requests from visitor browsers to unfamiliar domains when viewing Campus Directory pages
- New or modified administrator accounts following Contributor account activity
- Session cookies for privileged accounts appearing in web server referrer logs to external hosts
Detection Strategies
- Query the wp_postmeta and wp_options tables for noaccess_msg values containing HTML tags or script keywords
- Review Contributor and Author account activity in WordPress audit logs for edits to Campus Directory content
- Deploy a web application firewall (WAF) rule that flags script-like payloads submitted through Campus Directory form endpoints
Monitoring Recommendations
- Alert on Content Security Policy (CSP) violation reports originating from pages that embed Campus Directory shortcodes
- Monitor administrator sessions for concurrent logins from disparate IP addresses following visits to affected pages
- Track plugin version inventory across WordPress fleets to identify sites still running Campus Directory ≤ 1.9.1
How to Mitigate CVE-2025-8313
Immediate Actions Required
- Update the Campus Directory plugin to the version containing the fix from WordPress Changeset #3337642
- Audit existing Contributor and Author accounts and remove any that are unrecognized or inactive
- Review all pages rendering the noaccess_msg value and purge any content containing script payloads
- Rotate administrator session cookies and credentials if evidence of exploitation is present
Patch Information
The vendor addressed the flaw in a subsequent release tracked by WordPress Changeset #3337642. Refer to the Campus Directory Plugin Developers page for the latest release notes and download links.
Workarounds
- Restrict Contributor and Author role assignment to trusted users only until the patch is applied
- Deploy a WAF rule that strips <script> tags and event handler attributes from POST parameters targeting Campus Directory endpoints
- Enforce a strict Content Security Policy that disallows inline scripts on pages rendering plugin output
- Temporarily deactivate the Campus Directory plugin on sites where patching is not immediately feasible
# Configuration example: locate vulnerable installations via WP-CLI
wp plugin list --name=campus-directory --fields=name,status,version
wp plugin update campus-directory
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.