Junglewise Threat Intelligence

CVE-2025-23667: Christopher Churchill custom-post-edit reflected XSS

CVE-2025-23667 · Severity: high · CVSS 7.1 · Published 2025-12-31

Executive brief

The custom-post-edit WordPress plugin allows unauthenticated attackers to inject malicious JavaScript code that executes in the browsers of site visitors. An attacker can craft a malicious link and trick users into clicking it, enabling account hijacking, credential theft, or malware distribution to thousands of WordPress sites simultaneously.

Technical details

This vulnerability is a reflected Cross-Site Scripting (XSS) flaw in the custom-post-edit WordPress plugin through version 1.0.4, caused by improper neutralization of user input during web page generation. The vulnerability is accessible to unauthenticated attackers and requires user interaction (e.g., clicking a malicious link). Successful exploitation allows injection of arbitrary JavaScript that runs in the context of the victim's session, potentially leading to session hijacking, credential theft, or malware distribution. No official patch is currently available; Patchstack has issued a mitigation rule to block attacks.

Affected products

  • Christopher Churchill custom-post-edit through 1.0.4

Timeline

  • 2025-03-19: disclosed
  • 2025-12-31: advisory

References