Skip to main content

CVE-2025-9442: StreamWeasels Kick Integration XSS Flaw

CVE-2025-9442 is a stored cross-site scripting vulnerability in the StreamWeasels Kick Integration WordPress plugin that enables authenticated attackers to inject malicious scripts. This article covers technical details, affected versions, and mitigation strategies.

Published:

CVE-2025-9442 Overview

CVE-2025-9442 is a Stored Cross-Site Scripting (XSS) vulnerability in the StreamWeasels Kick Integration plugin for WordPress. The flaw affects all plugin versions up to and including 1.1.5. It stems from insufficient input sanitization and output escaping on the vodsChannel parameter used in the plugin's public display component.

Authenticated users with Contributor-level access or higher can inject arbitrary JavaScript into pages. The injected script executes in the browser of any visitor who loads an affected page, enabling session theft, forced redirects, and administrative actions if a privileged user views the content.

Critical Impact

Contributor-level accounts can persistently inject JavaScript that executes against every visitor, including site administrators, exposing sessions and enabling account takeover.

Affected Products

  • StreamWeasels Kick Integration plugin for WordPress
  • All versions up to and including 1.1.5
  • WordPress sites permitting Contributor-level (or higher) registration

Discovery Timeline

  • 2025-09-06 - CVE-2025-9442 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-9442

Vulnerability Analysis

The vulnerability is a Stored Cross-Site Scripting flaw classified under CWE-79. The plugin renders the vodsChannel shortcode attribute directly into HTML output through streamweasels-kick-vods-public-display.php without applying WordPress escaping functions such as esc_attr() or esc_html().

Because the payload is stored in post or page content, execution occurs every time a visitor loads the affected page. When an administrator views the injected content, the attacker's JavaScript runs with that administrator's session, enabling privilege escalation through actions like creating new admin users or modifying plugin settings.

Root Cause

The plugin accepts the vodsChannel parameter from user-supplied shortcode input and concatenates it into the page markup. The vulnerable rendering path is documented in the WordPress Plugin Code Snippet. No allowlist, sanitization callback, or context-aware output escaping is applied before the value reaches the browser.

Attack Vector

An authenticated attacker with Contributor privileges creates or edits a post containing the plugin's shortcode and supplies a malicious vodsChannel value. The payload persists in the WordPress database. When any user, including higher-privileged reviewers or administrators, previews or publishes the content, the browser interprets and executes the injected script.

The fix is delivered in WordPress Changeset #3355340, which introduces proper escaping on the affected parameter. Additional analysis is available from the Wordfence Vulnerability Analysis.

Detection Methods for CVE-2025-9442

Indicators of Compromise

  • Post or page content containing [sw-kick-vods] shortcode with vodsChannel values that include <script>, on*= event handlers, javascript: URIs, or encoded variants.
  • Unexpected WordPress user accounts created shortly after Contributor-authored content is reviewed by an administrator.
  • Outbound browser requests from admin sessions to unknown domains after loading pages that embed the plugin's VODs shortcode.

Detection Strategies

  • Query the wp_posts table for shortcode attributes containing angle brackets, event handlers, or URL-encoded script payloads in vodsChannel.
  • Deploy web application firewall (WAF) rules that inspect shortcode parameters submitted through the WordPress REST API and admin-ajax.php for XSS payloads.
  • Review WordPress audit logs for Contributor accounts submitting posts that contain the StreamWeasels Kick shortcode.

Monitoring Recommendations

  • Alert on new post revisions authored by Contributor-level accounts that include the plugin's shortcodes.
  • Monitor for administrator session anomalies such as unexpected user creation, role changes, or option updates following page previews.
  • Implement Content Security Policy (CSP) reporting to surface inline script violations originating from plugin-rendered pages.

How to Mitigate CVE-2025-9442

Immediate Actions Required

  • Update the StreamWeasels Kick Integration plugin to a version newer than 1.1.5 that includes the fix from changeset 3355340.
  • Audit existing posts and pages for injected vodsChannel payloads and remove or sanitize any suspicious content.
  • Review Contributor-level and above accounts, disabling any that are unrecognized or inactive.

Patch Information

The vendor addressed the flaw in WordPress Changeset #3355340 by applying output escaping to the vodsChannel parameter. Site owners should upgrade through the WordPress plugin manager or download the latest release from the StreamWeasels Plugin Developer Info page.

Workarounds

  • Temporarily deactivate the StreamWeasels Kick Integration plugin until the patched version is deployed.
  • Restrict Contributor role assignments and require Editor review before publishing content that uses the plugin's shortcodes.
  • Deploy a WAF rule that blocks HTML tags and JavaScript URIs inside the vodsChannel shortcode attribute.
bash
# Configuration example: WP-CLI commands to identify vulnerable installs and search for injected payloads
wp plugin get streamweasels-kick-integration --field=version
wp db query "SELECT ID, post_title FROM wp_posts WHERE post_content LIKE '%vodsChannel=%' AND (post_content LIKE '%<script%' OR post_content LIKE '%javascript:%' OR post_content LIKE '%onerror=%');"
wp plugin update streamweasels-kick-integration

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.