CVE-2025-8397 Overview
CVE-2025-8397 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Save as PDF Button plugin for WordPress. The flaw resides in the plugin's restpackpdfbutton shortcode and impacts all versions up to and including 1.9.2. Insufficient input sanitization and output escaping on user-supplied shortcode attributes allow authenticated users with contributor-level access or higher to inject arbitrary JavaScript. Injected scripts execute in the browser of any visitor who loads the affected page. The issue is tracked under CWE-79 and was published to the National Vulnerability Database (NVD) on November 13, 2025.
Critical Impact
Authenticated contributors can persist malicious JavaScript on WordPress pages, enabling session theft, account takeover of higher-privileged users, and drive-by delivery of secondary payloads to site visitors.
Affected Products
- Save as PDF Button plugin for WordPress — all versions ≤ 1.9.2
- WordPress sites permitting contributor-or-above registration
- Any WordPress deployment using the restpackpdfbutton shortcode
Discovery Timeline
- 2025-11-13 - CVE-2025-8397 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-8397
Vulnerability Analysis
The vulnerability exists in the plugin's shortcode handler for restpackpdfbutton. WordPress shortcodes accept attributes that authors embed within post or page content. When a contributor submits a post containing the shortcode, the plugin reads these attributes and reflects them into the rendered HTML without sufficient sanitization or output encoding. An attacker supplies JavaScript payloads through the shortcode attributes, and the payload persists in the database as part of the page content. When any visitor, including administrators, loads the page, the browser executes the attacker-controlled script in the site's origin.
Because the payload is stored, exploitation requires no social engineering beyond convincing a higher-privileged user to view the injected page — a routine occurrence during editorial review workflows on multi-author WordPress sites.
Root Cause
The root cause is missing input sanitization at the point the plugin parses shortcode attributes and missing output escaping when those attributes are rendered into HTML. WordPress provides functions such as sanitize_text_field(), esc_attr(), and esc_html() for exactly this purpose. Their absence in the shortcode handler allows raw attacker markup to reach the browser.
Attack Vector
Exploitation requires an authenticated account at contributor level or higher — a privilege tier many WordPress sites grant to guest authors, freelance writers, and community contributors. The attacker crafts a post or page that includes the restpackpdfbutton shortcode with a JavaScript payload placed in one of its attributes. Once the content is saved and later rendered, the payload executes in the browser context of anyone viewing the page. Because the scope changes across security boundaries, a contributor's injected script can act against an administrator's authenticated session. Refer to the Wordfence advisory and the plugin source for the vulnerable handler.
Detection Methods for CVE-2025-8397
Indicators of Compromise
- Post or page content containing the [restpackpdfbutton] shortcode with attribute values that include <script>, onerror=, onload=, javascript:, or encoded equivalents.
- Newly created or recently modified posts authored by contributor-tier accounts that embed the plugin's shortcode.
- Outbound HTTP requests from site visitors' browsers to unfamiliar third-party domains immediately after loading a page that uses the shortcode.
Detection Strategies
- Query the wp_posts table for post_content matching the restpackpdfbutton shortcode combined with common XSS tokens.
- Enable a Content Security Policy (CSP) in report-only mode and review violations tied to inline script execution on plugin-rendered pages.
- Audit user roles and identify accounts elevated to contributor or above that submitted content since the plugin was installed.
Monitoring Recommendations
- Log and alert on shortcode attribute strings containing HTML control characters submitted through the WordPress REST API or post.php.
- Monitor administrator sessions for unexpected cookie access, form injection, or redirect behavior on plugin-rendered pages.
- Track plugin version inventory across WordPress estates and flag any instance running Save as PDF Button ≤ 1.9.2.
How to Mitigate CVE-2025-8397
Immediate Actions Required
- Deactivate the Save as PDF Button plugin until a patched release is confirmed available and installed.
- Audit all posts and pages containing the [restpackpdfbutton] shortcode and remove or sanitize suspicious attribute values.
- Review contributor-and-above accounts, rotate credentials, and remove accounts that no longer require publishing access.
- Force a WordPress administrator session reset in case an injected script has already exfiltrated authentication cookies.
Patch Information
At the time of NVD publication, all versions up to and including 1.9.2 were affected. Administrators should consult the WordPress plugin page and the Wordfence vulnerability report for the latest fixed version, and update as soon as a patched release is published.
Workarounds
- Remove or restrict use of the restpackpdfbutton shortcode by filtering it out with a remove_shortcode('restpackpdfbutton') call in a mu-plugin until patched.
- Restrict the ability to publish or preview content containing the shortcode to trusted editor or administrator roles.
- Deploy a Web Application Firewall (WAF) rule that blocks POST requests to wp-admin/post.php and the REST API when shortcode attributes contain script tokens.
- Enforce a strict Content Security Policy that disallows inline scripts on public pages.
# Configuration example: temporarily disable the vulnerable shortcode
# Place this in wp-content/mu-plugins/disable-restpackpdfbutton.php
<?php
add_action('init', function () {
remove_shortcode('restpackpdfbutton');
add_shortcode('restpackpdfbutton', '__return_empty_string');
}, 99);
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.