Junglewise Threat Intelligence

CVE-2025-15659: Elizaibots WordPress plugin contributor XSS

CVE-2025-15659 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Executive brief

Elizaibots is a WordPress plugin used to integrate AI chatbots into websites. A security flaw allows users with contributor-level access to inject malicious scripts into the site. If an administrator views the affected content, the attacker could potentially hijack their session, redirect visitors to malicious websites, or deface the site.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the Elizaibots WordPress plugin (versions <= 1.0.2) due to improper neutralization of input during web page generation (CWE-79). The vulnerability requires 'Contributor' level privileges to inject a malicious payload. Successful exploitation occurs when a privileged user (such as an administrator) interacts with the affected page or component, triggering the execution of the script in their browser session. This can lead to session hijacking or unauthorized administrative actions. As of the advisory date, no official patch has been released.

Affected products

  • Elizaibots Elizaibots <= 1.0.2

Timeline

  • 2025-06-26: other: Vulnerability reported by researcher Mika
  • 2025-08-16: advisory: Initial Patchstack advisory published
  • 2026-06-15: disclosed: CVE published to NVD dataset

References