CVE-2025-9850 Overview
CVE-2025-9850 is a Stored Cross-Site Scripting (XSS) vulnerability in the Evenium plugin for WordPress. The flaw affects all versions up to and including 1.3.11. It resides in the plugin's evenium_single_event shortcode, which fails to sanitize user-supplied attributes and does not escape output before rendering. Authenticated users with contributor-level access or higher can inject arbitrary JavaScript that executes when other users view the affected page. The issue is classified under CWE-79: Improper Neutralization of Input During Web Page Generation.
Critical Impact
Contributor-level accounts can persist malicious scripts that execute in the browsers of administrators and site visitors, enabling session theft, account takeover, and content manipulation.
Affected Products
- Evenium plugin for WordPress — all versions through 1.3.11
- WordPress sites permitting contributor-level registration
- Any site using the evenium_single_event shortcode
Discovery Timeline
- 2025-09-11 - CVE-2025-9850 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-9850
Vulnerability Analysis
The Evenium plugin exposes the evenium_single_event shortcode to embed event data into WordPress pages and posts. The shortcode handler accepts user-supplied attributes and reflects them into rendered page output without applying sanitization functions such as sanitize_text_field() or escaping helpers such as esc_attr() and esc_html().
Because attribute values pass through to the HTML response unchanged, an attacker with edit access to any post or page can embed a shortcode instance carrying JavaScript payloads inside attribute values. When the containing page is rendered, the browser parses the injected markup and executes the script in the origin of the WordPress site.
The attack requires only contributor-level privileges. Contributors can author draft posts on many WordPress installations, so the barrier to storing a payload is low. The Wordfence advisory documents the sink in evenium_quicktags.php line 27.
Root Cause
The root cause is missing input sanitization and missing output escaping on shortcode attributes. The plugin trusts user-controlled values passed into the shortcode and concatenates them into HTML output. WordPress provides sanitization and escaping APIs specifically to prevent this class of flaw, and the plugin does not invoke them on the vulnerable code path.
Attack Vector
An authenticated attacker with contributor or higher privileges edits a post or page and inserts the evenium_single_event shortcode with a crafted attribute containing script content. When an editor, administrator, or public visitor loads the page, the payload executes in their browser session. Consequences include cookie theft, forced actions performed through the victim's authenticated session, redirection to attacker-controlled infrastructure, and defacement. Refer to the Wordfence Vulnerability Analysis for additional context.
Detection Methods for CVE-2025-9850
Indicators of Compromise
- Post or page content containing [evenium_single_event ...] shortcodes with attribute values that include <script>, onerror=, onload=, or javascript: fragments
- Unexpected outbound requests from browsers viewing WordPress pages to unfamiliar domains
- Newly created administrator accounts or role escalations following content edits by contributors
- WordPress posts table entries authored by contributor accounts that reference the vulnerable shortcode
Detection Strategies
- Query the WordPress database for post content containing the shortcode and inspect attribute values for HTML or script fragments
- Review the WordPress audit log for contributor accounts publishing or updating posts that use the Evenium shortcode
- Deploy a Web Application Firewall (WAF) rule that flags shortcode attributes containing angle brackets, event handlers, or javascript: schemes
Monitoring Recommendations
- Monitor for anomalous JavaScript execution on rendered pages using Content Security Policy (CSP) violation reports
- Alert on privilege changes, plugin installations, and administrator account creation immediately following contributor activity
- Track HTTP responses from WordPress URLs for reflected script tags matching known payload signatures
How to Mitigate CVE-2025-9850
Immediate Actions Required
- Update the Evenium plugin to a version later than 1.3.11 when one is published by the vendor
- Audit all posts and pages that use the evenium_single_event shortcode and remove any suspicious attribute values
- Review contributor and author accounts, disable unused accounts, and rotate credentials for accounts suspected of misuse
- Apply a virtual patch through a WordPress WAF that filters malicious shortcode attributes
Patch Information
At the time of the last NVD update on 2026-06-17, no fixed version is documented in the referenced advisories. Monitor the WordPress plugin repository and the Wordfence advisory for release information and apply the fixed version as soon as it is available.
Workarounds
- Deactivate the Evenium plugin until a patched release is available
- Restrict contributor and author registration; require administrator approval for new content-editing accounts
- Enforce a strict Content Security Policy (CSP) that blocks inline scripts and unauthorized script sources
- Use a WAF ruleset that inspects post save requests for XSS payloads within shortcode attributes
# Configuration example: disable the Evenium plugin via WP-CLI
wp plugin deactivate evenium
# Search for posts containing the vulnerable shortcode
wp db query "SELECT ID, post_title, post_author FROM wp_posts WHERE post_content LIKE '%[evenium_single_event%';"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.