Skip to main content

CVE-2025-8721: Workable Api WordPress Plugin XSS Vulnerability

CVE-2025-8721 is a stored cross-site scripting flaw in Workable Api WordPress plugin that allows authenticated attackers to inject malicious scripts. This article covers technical details, affected versions, and mitigation strategies.

Published:

CVE-2025-8721 Overview

CVE-2025-8721 is a stored Cross-Site Scripting (XSS) vulnerability in the Workable Api plugin for WordPress. The flaw affects all versions up to and including 1.0.4. It resides in the plugin's workable_jobs shortcode, which fails to sanitize user-supplied attributes and escape output. Authenticated users with contributor-level access or higher can inject arbitrary JavaScript into pages. The payload executes in the browser of any visitor viewing the affected page. The vulnerability is tracked under CWE-79 and carries a scope change, meaning script execution impacts resources beyond the vulnerable component.

Critical Impact

Authenticated contributors can inject persistent JavaScript that executes against administrators and visitors, enabling session theft, account takeover, or arbitrary administrative actions.

Affected Products

  • Workable Api plugin for WordPress (also referenced as wrapper-for-workable-api)
  • All versions up to and including 1.0.4
  • WordPress sites permitting contributor-level or higher registrations

Discovery Timeline

  • 2025-09-11 - CVE-2025-8721 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-8721

Vulnerability Analysis

The Workable Api plugin exposes a workable_jobs shortcode that accepts user-supplied attributes. The plugin passes these attributes into rendered HTML without applying WordPress sanitization functions such as esc_attr(), esc_html(), or wp_kses(). As a result, attacker-controlled input reaches the DOM verbatim.

Because the shortcode is embedded in posts or pages, injected payloads persist in the database. Every subsequent render triggers the payload in the visitor's browser session. An attacker with contributor privileges can therefore weaponize the shortcode against higher-privileged users who preview or review the affected content.

Exploitation requires authentication but no user interaction beyond visiting the affected page. The scope change reflected in the CVSS vector indicates the injected script can act on data belonging to other users and origins beyond the plugin itself.

Root Cause

The root cause is insufficient input sanitization and missing output escaping in the shortcode handler defined within workable-api.php. WordPress shortcode APIs require developers to explicitly sanitize attributes returned by shortcode_atts() before rendering them. The plugin omits this step, allowing HTML and JavaScript payloads passed via shortcode attributes to be echoed directly into the response body.

Attack Vector

An authenticated attacker with contributor-level access creates a post or page containing the workable_jobs shortcode with a malicious attribute value carrying a JavaScript payload, such as an onerror handler embedded inside an HTML tag. When an editor, administrator, or site visitor accesses the resulting page, the browser parses and executes the payload under the WordPress site's origin. See the Wordfence Vulnerability Report and the WordPress Plugin File for technical details of the vulnerable handler.

Detection Methods for CVE-2025-8721

Indicators of Compromise

  • Posts or pages containing [workable_jobs] shortcodes with attribute values that include <script>, onerror=, onload=, javascript:, or encoded variants.
  • Unexpected <script> tags rendered in job listing pages served by the plugin.
  • New contributor or author accounts created shortly before shortcode content is added.
  • Outbound requests from visitor browsers to unfamiliar domains after loading affected pages.

Detection Strategies

  • Query the WordPress wp_posts table for post_content LIKE '%[workable_jobs%' and inspect attribute values for HTML or script fragments.
  • Deploy a web application firewall rule that flags shortcode attributes containing angle brackets or JavaScript event handlers.
  • Review WordPress audit logs for content edits performed by contributor-level accounts on pages using the plugin's shortcode.

Monitoring Recommendations

  • Enable Content Security Policy (CSP) reporting to surface unexpected inline script execution on published pages.
  • Monitor administrator sessions for anomalous API calls originating from browser sessions immediately after viewing plugin-rendered content.
  • Track installed plugin versions across the WordPress fleet and alert when wrapper-for-workable-api is present at version 1.0.4 or earlier.

How to Mitigate CVE-2025-8721

Immediate Actions Required

  • Deactivate and remove the Workable Api plugin until a patched release is confirmed available and installed.
  • Audit all pages and posts referencing the workable_jobs shortcode and remove any suspicious attribute content.
  • Restrict contributor-level registrations and review recently created low-privilege accounts.
  • Rotate credentials and session tokens for administrators who may have loaded affected pages.

Patch Information

At the time of NVD publication, no fixed version beyond 1.0.4 is referenced in the advisory. Consult the WordPress Plugin Developer Info page for the latest release information and apply any vendor-supplied update immediately once available.

Workarounds

  • Remove the plugin entirely if a patched version has not been published.
  • Enforce least privilege by limiting the unfiltered_html capability and reviewing the roles allowed to publish or preview content.
  • Deploy a strict Content Security Policy that disallows inline scripts on pages rendered by the plugin.
  • Add a WAF rule blocking shortcode attribute values containing <, >, or JavaScript event handler substrings.
bash
# Configuration example: disable and remove the vulnerable plugin via WP-CLI
wp plugin deactivate wrapper-for-workable-api
wp plugin delete wrapper-for-workable-api

# Identify posts that reference the vulnerable shortcode for manual review
wp db query "SELECT ID, post_title, post_status FROM wp_posts \
  WHERE post_content LIKE '%[workable_jobs%';"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.