CVE-2025-9061 Overview
The Wilmer Core plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability [CWE-79] affecting all versions up to and including 2.4.5. The flaw resides in the plugin's shortcode handling, where user-supplied attributes are neither properly sanitized on input nor escaped on output. Authenticated users with contributor-level permissions or higher can inject arbitrary JavaScript that executes in the browser of any visitor who loads the affected page. The Wilmer Core plugin ships with the Wilmr Construction WordPress theme distributed on ThemeForest.
Critical Impact
Authenticated contributors can persist malicious JavaScript into WordPress pages, enabling session theft, administrative account takeover, and redirection of site visitors.
Affected Products
- Wilmer Core plugin for WordPress, versions <= 2.4.5
- Wilmr Construction WordPress theme deployments bundling the Wilmer Core plugin
- WordPress sites permitting contributor-level accounts to author shortcode content
Discovery Timeline
- 2025-09-09 - CVE-2025-9061 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-9061
Vulnerability Analysis
The vulnerability is a Stored Cross-Site Scripting flaw exposed through one or more shortcodes registered by the Wilmer Core plugin. Shortcodes in WordPress accept attributes supplied by content authors and expand into rendered HTML at page load. When these attributes are echoed into markup without contextual escaping, attacker-controlled strings become executable script in the visitor's browser.
Because the payload is stored in the post or page content, exploitation is persistent. Every visitor rendering the affected page executes the injected script under the site's origin. The attack scope is changed, meaning the malicious script runs in the trust context of the WordPress site and can reach cookies, session tokens, and DOM state belonging to authenticated administrators.
Root Cause
The root cause is insufficient input sanitization combined with missing output escaping on shortcode attribute values. WordPress provides helpers such as sanitize_text_field() for input filtering and esc_attr() or esc_html() for output escaping. The affected shortcode handlers fail to apply these controls before concatenating attribute data into rendered HTML.
Attack Vector
An attacker requires a contributor-level account or higher on the target WordPress site. The attacker authors or edits a post that includes a vulnerable Wilmer Core shortcode and passes a crafted attribute containing HTML or JavaScript. When the post is previewed, published, or otherwise viewed, the payload executes in the visitor's browser. See the Wordfence Vulnerability Report for additional detail on the affected shortcodes.
Detection Methods for CVE-2025-9061
Indicators of Compromise
- Post or page content in wp_posts containing Wilmer Core shortcodes with attribute values that include <script>, onerror=, onload=, or javascript: sequences.
- Unexpected outbound requests from visitor browsers to attacker-controlled domains originating from pages that render Wilmer Core shortcodes.
- New or modified administrator accounts created shortly after a contributor account edited pages containing Wilmer Core shortcodes.
Detection Strategies
- Query the WordPress database for shortcode invocations bound to the plugin and inspect attribute payloads for HTML control characters or script keywords.
- Review audit logs for contributor-level users editing published pages, particularly edits that introduce shortcode markup.
- Monitor web server access logs for requests to pages known to render Wilmer Core shortcodes and correlate with anomalous referrers or client-side error telemetry.
Monitoring Recommendations
- Enable a Content Security Policy (CSP) in report-only mode to surface inline script violations on pages rendered by the plugin.
- Alert on creation or privilege escalation of WordPress user accounts, especially those elevated from contributor to editor or administrator.
- Track plugin version changes and confirm Wilmer Core is upgraded past 2.4.5 across all managed WordPress instances.
How to Mitigate CVE-2025-9061
Immediate Actions Required
- Update the Wilmer Core plugin to a version later than 2.4.5 as soon as the vendor releases a fix.
- Audit all contributor, author, and editor accounts and remove any that are inactive, unrecognized, or unnecessary.
- Review recent edits to pages and posts containing Wilmer Core shortcodes and remove any attribute values containing HTML or script content.
Patch Information
At the time of publication, verify the availability of a patched release through the vendor's distribution channel on ThemeForest. Consult the Wordfence Vulnerability Report for tracking of fixed versions.
Workarounds
- Restrict contributor and author roles from editing posts that use Wilmer Core shortcodes until the plugin is updated.
- Deploy a web application firewall (WAF) rule that blocks POST requests containing shortcode attributes with <, >, or javascript: substrings targeting the WordPress editor endpoints.
- Apply a strict Content Security Policy that disallows inline scripts, reducing the impact of any successful injection.
# Configuration example: enforce a restrictive CSP header in Nginx
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'" always;
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.