CVE-2025-8623 Overview
The WeedMaps Menu for WordPress plugin contains a stored Cross-Site Scripting (XSS) vulnerability in the weedmaps_menu shortcode. All versions up to and including 1.2.0 fail to properly sanitize input and escape output on user-supplied shortcode attributes. Authenticated users holding contributor-level access or higher can inject arbitrary JavaScript into pages. The injected script executes in the browser of any visitor who loads the affected page. The flaw is classified under CWE-79: Improper Neutralization of Input During Web Page Generation.
Critical Impact
Authenticated contributors can persist arbitrary JavaScript on WordPress pages, enabling session theft, forced redirects, and administrator account takeover when a privileged user views the injected content.
Affected Products
- WeedMaps Menu for WordPress plugin — all versions through 1.2.0
- WordPress sites running the vulnerable plugin with contributor-level user registration enabled
- Any site using the weedmaps_menu shortcode functionality
Discovery Timeline
- 2025-09-30 - CVE-2025-8623 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-8623
Vulnerability Analysis
The vulnerability resides in the plugin's weedmaps_menu shortcode handler. The handler accepts user-controlled attributes and renders them into HTML output without applying WordPress sanitization functions such as esc_attr(), esc_html(), or wp_kses(). When a contributor embeds the shortcode in a post or page with malicious attribute values, the plugin writes the attacker's payload directly into the DOM at render time.
Stored XSS in a WordPress context is high leverage because the payload persists in the database and executes for every viewer of the affected page. When an administrator previews or publishes the contributor's submission, the script runs with the administrator's session, enabling actions such as creating new admin accounts, installing plugins, or exfiltrating nonces.
Root Cause
The root cause is missing input sanitization and missing output escaping on shortcode attributes processed by the plugin. Shortcode attribute values arrive as untrusted user input but are echoed into HTML without contextual escaping. Refer to the WordPress Plugin Code for the vulnerable implementation.
Attack Vector
An authenticated attacker with contributor role or above creates or edits a post and inserts the weedmaps_menu shortcode with a crafted attribute containing JavaScript. Once the post is viewed, whether as a preview by an editor, an approved published page, or a scheduled post, the injected script executes in the visitor's browser under the site's origin. See the Wordfence Vulnerability Report for additional technical detail.
Detection Methods for CVE-2025-8623
Indicators of Compromise
- Posts or pages containing [weedmaps_menu] shortcodes with attribute values that include <script>, onerror=, onload=, javascript:, or encoded HTML entities
- Unexpected creation of new WordPress administrator accounts following contributor submissions
- Outbound requests from site visitors to attacker-controlled domains sourced from published pages
- WordPress wp_posts table rows authored by contributors containing HTML event handlers within shortcode arguments
Detection Strategies
- Query the wp_posts table for post_content matching the weedmaps_menu shortcode combined with suspicious characters such as <, >, or on\w+=
- Review contributor and author activity logs for posts submitted for review that contain shortcode attributes
- Deploy a Web Application Firewall (WAF) rule that blocks HTML tags and event handlers within shortcode attribute values
Monitoring Recommendations
- Monitor administrator session activity for unusual actions such as plugin installation or user creation immediately after previewing contributor content
- Log and alert on modifications to the wp_users and wp_usermeta tables outside of expected administrative workflows
- Track requests to admin-ajax.php and REST API endpoints originating from browsers loading contributor-authored pages
How to Mitigate CVE-2025-8623
Immediate Actions Required
- Deactivate and remove the WeedMaps Menu for WordPress plugin until a patched version is confirmed available
- Audit all existing posts and pages for the weedmaps_menu shortcode and remove or sanitize any suspicious attribute values
- Review contributor and author accounts, disabling any that are unused or unverified
- Rotate credentials for any administrator account that may have previewed contributor-submitted content
Patch Information
At the time of the NVD entry, all versions through 1.2.0 are affected. Consult the WordPress Plugin Developer Info page for the latest release status and apply any published update that addresses shortcode attribute sanitization.
Workarounds
- Restrict user registration and revoke contributor-or-higher roles from untrusted accounts
- Require editorial review of all contributor submissions before publication, with reviewers using a browser profile without active administrator sessions
- Apply a WAF rule that strips <script> tags and inline event handlers from POST bodies targeting wp-admin/post.php
- Enforce a strict Content Security Policy (CSP) that disallows inline script execution on public pages
# Example WordPress CLI command to locate posts containing the vulnerable shortcode
wp db query "SELECT ID, post_author, post_status FROM wp_posts \
WHERE post_content LIKE '%[weedmaps_menu%' \
AND (post_content REGEXP '<script|on[a-z]+=|javascript:');"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.