Skip to main content

CVE-2025-9852: Yoga Schedule Momoyoga XSS Vulnerability

CVE-2025-9852 is a stored XSS vulnerability in the Yoga Schedule Momoyoga WordPress plugin that lets authenticated attackers inject malicious scripts. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2025-9852 Overview

The Yoga Schedule Momoyoga plugin for WordPress contains a stored Cross-Site Scripting (XSS) vulnerability in the momoyoga-schedule shortcode. The flaw affects all plugin versions up to and including 2.9.0. Insufficient input sanitization and output escaping on user-supplied shortcode attributes allow authenticated attackers with contributor-level access or higher to inject arbitrary JavaScript. The injected scripts execute in the browser of any user who visits an affected page. The issue is tracked as CWE-79 and was resolved in version 2.9.1.

Critical Impact

Contributor-level accounts can persist arbitrary JavaScript that executes in the browsers of site visitors and administrators, enabling session theft, account takeover, and content manipulation.

Affected Products

  • Yoga Schedule Momoyoga plugin for WordPress, versions up to and including 2.9.0
  • The vulnerable code resides in momoyoga-schedule.php
  • Fixed in Yoga Schedule Momoyoga version 2.9.1

Discovery Timeline

  • 2025-09-30 - CVE-2025-9852 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-9852

Vulnerability Analysis

The vulnerability is a stored Cross-Site Scripting (XSS) flaw classified under [CWE-79]. It resides in the plugin's momoyoga-schedule shortcode handler defined in momoyoga-schedule.php. When the shortcode is rendered, user-supplied attributes are inserted into the HTML output without adequate sanitization or escaping.

An authenticated user with the contributor role or higher can embed the shortcode inside a post or page and pass malicious attribute values. Because contributor accounts can create draft content, the barrier to exploitation is low on sites that permit open registration or maintain many low-privilege accounts. The injected payload executes whenever a reviewer, editor, or site visitor loads the affected page.

Successful exploitation permits session cookie theft, forced administrative actions through CSRF chaining, defacement, and redirection to attacker-controlled infrastructure. Refer to the Wordfence Vulnerability Report for additional context.

Root Cause

The plugin accepts shortcode attributes and emits them into rendered HTML without calling appropriate WordPress escaping functions such as esc_attr(), esc_html(), or wp_kses(). Any string passed by the author is treated as trusted markup. The vulnerable rendering path is visible in the pre-patch source at line 56 of momoyoga-schedule.php.

Attack Vector

An authenticated contributor authors a post containing the [momoyoga-schedule] shortcode with an attribute value crafted to break out of the intended HTML context and inject a <script> element or an event-handler attribute. When the post is previewed, reviewed, or published, the payload runs in the victim's browser under the site's origin. See the patched source in version 2.9.1 for the corrected escaping logic.

Detection Methods for CVE-2025-9852

Indicators of Compromise

  • Post or page content containing [momoyoga-schedule ...] shortcodes with attribute values that include HTML tags, quotes, or JavaScript keywords such as onerror, onload, javascript:, or <script>.
  • Unexpected outbound requests from browsers viewing plugin-generated schedule pages, particularly to unknown domains.
  • New or modified draft or published posts authored by contributor accounts that reference the plugin shortcode.

Detection Strategies

  • Query the wp_posts table for post_content values that match the plugin shortcode combined with suspicious attribute payloads.
  • Enable WordPress audit logging to track shortcode-bearing content edits by contributor and author roles.
  • Deploy a web application firewall (WAF) rule that inspects POST requests to wp-admin/post.php for reflected XSS patterns inside shortcode attributes.

Monitoring Recommendations

  • Alert on browser Content Security Policy (CSP) violation reports originating from pages rendered by the Momoyoga plugin.
  • Monitor administrator sessions for anomalous activity, such as unexpected user creation or plugin installation, following review of contributor drafts.
  • Track plugin version inventory across managed WordPress sites and flag any instance running 2.9.0 or earlier.

How to Mitigate CVE-2025-9852

Immediate Actions Required

  • Update the Yoga Schedule Momoyoga plugin to version 2.9.1 or later on all WordPress installations.
  • Audit contributor and author accounts, remove unused users, and enforce strong authentication for remaining low-privilege roles.
  • Review published and draft content for existing [momoyoga-schedule] shortcodes containing suspicious attribute values and sanitize or remove them.

Patch Information

The vendor addressed the flaw in Yoga Schedule Momoyoga version 2.9.1. The fix introduces proper output escaping on the shortcode attributes rendered in momoyoga-schedule.php. Compare the vulnerable 2.9.0 source with the patched 2.9.1 source to validate the corrected escaping.

Workarounds

  • Deactivate the Yoga Schedule Momoyoga plugin until it can be upgraded to 2.9.1.
  • Restrict shortcode usage by removing the contributor role's ability to publish content that includes plugin shortcodes, using a role-management plugin.
  • Deploy a WAF rule that blocks HTML metacharacters inside momoyoga-schedule shortcode attributes at the edge.
bash
# Configuration example: update the plugin using WP-CLI
wp plugin update momoyoga-integration --version=2.9.1
wp plugin list --name=momoyoga-integration --fields=name,status,version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.