Skip to main content

CVE-2025-9344: UsersWP WordPress Plugin XSS Vulnerability

CVE-2025-9344 is a stored XSS flaw in UsersWP WordPress plugin affecting shortcode attributes. Authenticated attackers can inject malicious scripts into pages. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2025-9344 Overview

CVE-2025-9344 is a Stored Cross-Site Scripting (XSS) vulnerability in the UsersWP plugin for WordPress. The plugin provides front-end login forms, user registration, user profiles, and a members directory. The flaw affects all versions up to and including 1.2.42 and stems from insufficient input sanitization and output escaping on user-supplied attributes in the uwp_profile and uwp_profile_header shortcodes. Authenticated attackers with contributor-level access or above can inject arbitrary web scripts into pages, which execute when other users view the affected content. The vulnerability is classified under [CWE-79] (Improper Neutralization of Input During Web Page Generation).

Critical Impact

Contributor-level authenticated attackers can inject persistent JavaScript that executes in the context of any visitor, enabling session theft, admin account takeover, and site defacement.

Affected Products

  • UsersWP plugin for WordPress, all versions up to and including 1.2.42
  • uwp_profile shortcode handler
  • uwp_profile_header shortcode handler (templates/bootstrap/profile-header.php)

Discovery Timeline

  • 2025-08-28 - CVE-2025-9344 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-9344

Vulnerability Analysis

The vulnerability resides in how the UsersWP plugin renders shortcode attributes back into HTML output. When the uwp_profile or uwp_profile_header shortcodes are processed, the disable_greedy attribute value is concatenated directly into a nested shortcode string without escaping. The resulting content is then passed to do_shortcode() and echoed to the page. Because contributors can embed shortcodes in posts they author, an attacker with contributor privileges can craft attribute values containing HTML or JavaScript payloads that persist in the database.

When a reviewer, editor, or administrator views the injected content, the script executes in their browser session. This enables account takeover through cookie theft, forced administrative actions via CSRF, or delivery of second-stage payloads. The scope change reflects that the injected script executes in the browser trust boundary of any visiting user, not just the attacker.

Root Cause

The root cause is missing output escaping on the disable_greedy shortcode argument before it is interpolated into a downstream shortcode invocation. The pre-patch code path built the inner shortcode as a raw string using untrusted attribute data, bypassing WordPress's normal escaping conventions for attribute contexts.

Attack Vector

An authenticated user with contributor-level access or higher inserts a uwp_profile or uwp_profile_header shortcode into a post or page with a malicious disable_greedy attribute value. The payload is stored server-side and rendered whenever the page is loaded, executing arbitrary JavaScript in the victim's browser.

php
// Vulnerable code from templates/bootstrap/profile-header.php
<?php echo do_shortcode( "[uwp_user_post_counts disable_greedy=".$args['disable_greedy']."]" ); ?>

// Patched code applies esc_attr() to sanitize the attribute
<?php echo do_shortcode( "[uwp_user_post_counts disable_greedy=".esc_attr($args['disable_greedy'])."]" ); ?>

Source: GitHub Commit on UsersWP

Detection Methods for CVE-2025-9344

Indicators of Compromise

  • Post or page content containing uwp_profile or uwp_profile_header shortcodes with unexpected characters such as quotes, angle brackets, or javascript: payloads in the disable_greedy attribute.
  • New or modified posts authored by contributor-level accounts that include UsersWP shortcodes.
  • Unexpected outbound requests from administrator browsers to attacker-controlled domains after viewing plugin-rendered pages.

Detection Strategies

  • Query the wp_posts table for post_content matching uwp_profile or uwp_profile_header with attribute values containing <, >, ", or script.
  • Review web server logs for POST requests to /wp-admin/post.php or the REST API from contributor accounts creating or updating content with UsersWP shortcodes.
  • Deploy web application firewall rules that inspect shortcode attribute payloads for HTML or JavaScript tokens.

Monitoring Recommendations

  • Alert on privilege escalation events, new administrator accounts, or role modifications following contributor content submissions.
  • Monitor for unauthorized changes to wp_options and the active theme or plugin list, which XSS payloads commonly target.
  • Track anomalous session activity, including administrator sessions originating from unfamiliar IP addresses or user agents.

How to Mitigate CVE-2025-9344

Immediate Actions Required

  • Upgrade the UsersWP plugin to a version later than 1.2.42 that includes the esc_attr() fix committed in 2e18c3f.
  • Audit all existing pages and posts containing uwp_profile or uwp_profile_header shortcodes and remove any suspicious attribute values.
  • Review contributor and author accounts for signs of compromise and rotate credentials for any accounts that authored suspect content.

Patch Information

The vendor patched the vulnerability by wrapping the disable_greedy attribute value with esc_attr() before passing it into do_shortcode(). Details are available in the GitHub Commit on UsersWP, the WordPress Plugin Changeset, and the Wordfence Vulnerability Report.

Workarounds

  • Restrict contributor-level account creation and require administrator approval before granting shortcode-capable roles.
  • Deploy a WordPress-aware web application firewall to filter malicious shortcode attribute payloads until patching is complete.
  • Temporarily disable the UsersWP plugin on sites that cannot be updated immediately, especially those permitting untrusted contributors.
bash
# Update the UsersWP plugin using WP-CLI
wp plugin update userswp

# Verify the installed version is greater than 1.2.42
wp plugin get userswp --field=version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.