Skip to main content

CVE-2025-9493: Admin Menu Editor WordPress XSS Vulnerability

CVE-2025-9493 is a stored XSS vulnerability in the Admin Menu Editor WordPress plugin allowing authenticated attackers with Author-level access to inject malicious scripts. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2025-9493 Overview

CVE-2025-9493 is a Stored Cross-Site Scripting (XSS) vulnerability in the Admin Menu Editor plugin for WordPress. The flaw affects all versions up to and including 1.14. It originates in the handling of the placeholder parameter within the plugin's shortcode processing, where input is neither sufficiently sanitized nor properly escaped on output. Authenticated users with Author-level privileges or higher can inject arbitrary JavaScript into pages. The payload executes in the browser of any user who views the affected page, enabling session theft, forced actions, and account takeover escalation paths. The weakness is tracked under CWE-79.

Critical Impact

Authenticated Author-level attackers can store JavaScript that executes against administrators, enabling privilege escalation on WordPress sites running Admin Menu Editor ≤ 1.14.

Affected Products

  • Admin Menu Editor plugin for WordPress — all versions through 1.14
  • WordPress sites allowing Author-level or higher accounts to use plugin shortcodes
  • Sites exposing injected pages to administrator or editor viewers

Discovery Timeline

  • 2025-09-06 - CVE-2025-9493 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-9493

Vulnerability Analysis

The Admin Menu Editor plugin exposes shortcode functionality defined in includes/shortcodes.php. The shortcode accepts a placeholder attribute that is rendered into page output. In versions through 1.14, the plugin does not apply sufficient input sanitization on the attribute value and fails to apply contextual output escaping when writing the value back into HTML. Any script tags or event handler payloads supplied by a user with shortcode-authoring privileges persist in the post content and execute each time the page is rendered. Because WordPress Authors can create and publish posts, the attack surface is reachable without administrative access. Review the vulnerable shortcode source and the upstream fix in changeset 3353790 for details.

Root Cause

The root cause is improper neutralization of input during web page generation [CWE-79]. The placeholder shortcode attribute is passed into the rendered DOM without a sanitizer such as wp_kses or an escaper such as esc_attr or esc_html. Attacker-controlled markup is therefore interpreted as live HTML and JavaScript when the containing post or page is viewed.

Attack Vector

An attacker first obtains an account with Author-level privileges or higher, either through registration on sites that permit it or via credential compromise. The attacker then creates or edits a post containing the plugin shortcode with a crafted placeholder value carrying a JavaScript payload. When any logged-in user — including administrators — browses the page, the script runs in that user's session context. Typical outcomes include administrator cookie theft, creation of new admin accounts via authenticated AJAX requests, insertion of backdoored plugins, and redirection of visitors to attacker-controlled infrastructure.

See the Wordfence vulnerability analysis for additional technical context. No verified proof-of-concept code is published.

Detection Methods for CVE-2025-9493

Indicators of Compromise

  • Post or page content containing Admin Menu Editor shortcodes with placeholder attribute values that include <script>, onerror=, onload=, javascript:, or encoded equivalents.
  • Unexpected creation of new administrator-level WordPress accounts shortly after Author-level users publish or edit content.
  • Outbound browser requests from admin sessions to unfamiliar domains when viewing content authored by non-privileged users.
  • Modifications to active plugins or theme files following Author account activity.

Detection Strategies

  • Query the wp_posts table for shortcode patterns containing suspicious characters inside the placeholder attribute, for example placeholder="<, placeholder="javascript:, or percent-encoded script fragments.
  • Enable WordPress audit logging to correlate post edits by Author-level accounts with subsequent privileged user actions.
  • Deploy a web application firewall rule that inspects stored post content and request parameters for shortcode payloads carrying HTML control characters.

Monitoring Recommendations

  • Monitor the installed version of the Admin Menu Editor plugin across managed WordPress estates and alert on any instance at or below 1.14.
  • Alert on new user registrations with elevated roles and on role changes applied outside of normal administrative workflows.
  • Capture and review browser Content Security Policy (CSP) violation reports from /wp-admin/ sessions to surface injected inline scripts.

How to Mitigate CVE-2025-9493

Immediate Actions Required

  • Update the Admin Menu Editor plugin to the version published after changeset 3353790, which adds proper sanitization and escaping for the placeholder attribute.
  • Audit all existing posts and pages for the plugin's shortcode and remove or sanitize any placeholder values containing HTML or script characters.
  • Review the WordPress user list for unexpected administrator accounts and rotate credentials for all privileged users.
  • Restrict Author-level and higher accounts to trusted individuals and disable open user registration where it is not required.

Patch Information

The maintainer corrected the issue in the Admin Menu Editor plugin after version 1.14. Review the official plugin page for the current release and apply the update through the WordPress plugin management interface. The code change is documented in WordPress plugin changeset 3353790.

Workarounds

  • If immediate patching is not possible, deactivate the Admin Menu Editor plugin until the update is applied.
  • Temporarily restrict shortcode usage by Author-level accounts through a role-management plugin or custom capability filter.
  • Deploy a Content Security Policy that disallows inline scripts in rendered post content to limit payload execution.
  • Place the WordPress site behind a web application firewall configured to block shortcode attributes containing HTML tag characters.
bash
# Verify installed plugin version via WP-CLI and update to the latest release
wp plugin get admin-menu-editor --field=version
wp plugin update admin-menu-editor

# Search post content for suspicious shortcode usage
wp db query "SELECT ID, post_title FROM wp_posts WHERE post_content REGEXP 'placeholder=\"[^\"]*(<|javascript:|onerror=|onload=)'"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.