Junglewise Threat Intelligence

CVE-2025-5085: Kayes WP Nano AD Stored XSS in blogrole_link parameter

CVE-2025-5085 · Severity: medium · CVSS 5.5 · Published 2026-06-02

Executive brief

The WP Nano AD plugin for WordPress, used for managing advertising links, contains a security flaw that allows administrators to inject malicious scripts into the website. While this requires high-level access, it can be used in multi-site environments to target other users or bypass security restrictions. If exploited, these scripts execute automatically when other users visit the affected administrative pages, potentially leading to unauthorized actions or data theft.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the WP Nano AD plugin for WordPress due to improper neutralization of the 'blogrole_link' parameter in the add_links.php file. Authenticated attackers with administrator-level privileges can inject arbitrary web scripts into the database, which are then executed in the context of a user's browser when they access the modified record or links page. This vulnerability primarily impacts WordPress multi-site installations or environments where the 'unfiltered_html' capability has been disabled for administrators. The plugin has been closed on the WordPress repository as of May 2026 pending review, and no official patch has been confirmed.

Affected products

  • Kayes WP Nano AD up to, and including, 1.31

Timeline

  • 2026-05-27: other: Plugin temporarily closed on WordPress.org repository
  • 2026-06-02: disclosed: CVE published

References