CVE-2025-8604 Overview
CVE-2025-8604 is a Stored Cross-Site Scripting (XSS) vulnerability in the WP Table Builder – WordPress Table Plugin. The flaw affects all versions up to and including 2.0.12. The plugin fails to properly sanitize input and escape output on user-supplied attributes passed to the wptb shortcode. Authenticated attackers with contributor-level access or higher can inject arbitrary JavaScript into pages. The injected scripts execute in the browser of any user who visits an affected page, enabling session theft, forced redirects, or actions performed on behalf of higher-privileged users. The vulnerability is tracked under CWE-79.
Critical Impact
Contributor-level users can persistently inject JavaScript that executes in every visitor's browser, including administrators, enabling account takeover and site compromise.
Affected Products
- WP Table Builder – WordPress Table Plugin, all versions through 2.0.12
- WordPress sites permitting contributor-level (or higher) registration or account creation
- Any site rendering wptb shortcode content generated by untrusted authors
Discovery Timeline
- 2025-08-15 - CVE-2025-8604 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-8604
Vulnerability Analysis
The vulnerability resides in the plugin's wptb shortcode handler, which accepts attributes controlled by the content author. The plugin renders these attributes into HTML output without adequate sanitization or contextual escaping. As a result, an attacker who can create or edit posts can embed shortcode attributes containing script payloads. The malicious markup is stored in the database and served to every subsequent viewer of the affected page. Because contributor accounts are commonly permitted on multi-author WordPress sites, the barrier to exploitation is low. Successful exploitation runs attacker-controlled JavaScript in the context of the site origin, which can be used to hijack administrator sessions, insert backdoor accounts, or pivot to further plugin abuse.
Root Cause
The root cause is missing input sanitization and missing output escaping on shortcode attributes processed by the wptb handler in inc/admin/class-tables.php. WordPress provides helpers such as esc_attr(), esc_html(), and wp_kses() that should be applied when rendering user-controlled values, but they are not consistently enforced along this code path. The stored data is trusted at render time, producing a classic stored XSS pattern.
Attack Vector
An attacker authenticates to WordPress with contributor privileges or higher. The attacker creates or edits a post containing a wptb shortcode with a crafted attribute value that closes the intended HTML context and injects a <script> tag or event handler. Once the post is viewed, whether by an anonymous visitor, an editor, or an administrator, the payload executes in the victim's browser under the site's origin. See the Wordfence Vulnerability Report and the upstream code reference for the affected function.
No verified proof-of-concept code is published. The vulnerability mechanism is a standard shortcode-attribute XSS pattern; refer to the vendor patch changeset for the remediation diff.
Detection Methods for CVE-2025-8604
Indicators of Compromise
- Posts or pages containing [wptb ...] shortcodes with attribute values that include <script, onerror=, onload=, javascript:, or encoded variants
- New or modified administrator accounts created shortly after a contributor authored or edited a post using the wptb shortcode
- Outbound browser requests from site visitors to unfamiliar domains sourced from pages containing WP Table Builder content
Detection Strategies
- Query the wp_posts table for post_content matching wptb shortcodes and inspect attributes for HTML control characters or script keywords
- Deploy a web application firewall rule that inspects rendered responses for <script> tags emitted from within shortcode-generated markup
- Review WordPress audit logs for contributor accounts that submitted or updated content invoking WP Table Builder shortcodes
Monitoring Recommendations
- Enable and centralize WordPress activity logging, including user role changes and post revisions, to identify suspicious contributor behavior
- Monitor Content Security Policy (CSP) violation reports for inline script execution on pages hosted by the WordPress installation
- Alert on newly registered administrator accounts and unexpected plugin or theme file modifications following contributor activity
How to Mitigate CVE-2025-8604
Immediate Actions Required
- Update WP Table Builder to a version greater than 2.0.12 that includes the fix committed in the referenced plugin changeset
- Audit contributor, author, and editor accounts, revoking any that are unnecessary or inactive
- Review existing posts for wptb shortcodes containing suspicious attribute payloads and sanitize or remove them
Patch Information
The vendor addressed the flaw upstream in the WP Table Builder repository. Administrators should upgrade through the WordPress plugin installer or download the current release from the official plugin page. Confirm the installed version reports higher than 2.0.12 after upgrade.
Workarounds
- Restrict content authoring to trusted users and disable open user registration until the plugin is patched
- Deploy a WAF rule to strip or block <script> tags and event-handler attributes emitted through wptb shortcodes
- Temporarily deactivate the WP Table Builder plugin if an immediate upgrade is not possible
# Configuration example: upgrade WP Table Builder via WP-CLI
wp plugin update wp-table-builder
wp plugin get wp-table-builder --field=version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
