VYPR
Medium severity6.4NVD Advisory· Published Jun 14, 2025· Updated Apr 15, 2026

CVE-2025-5589

CVE-2025-5589

Description

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-classic-offline-text’ parameter in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated stored XSS in StreamWeasels Kick Integration plugin ≤1.1.3 via `status-classic-offline-text` parameter, allowing Contributor+ users to inject arbitrary scripts.

Root

Cause The StreamWeasels Kick Integration plugin for WordPress fails to sanitize and escape the status-classic-offline-text parameter, leading to Stored Cross-Site Scripting (XSS) [1]. This flaw affects all versions up to and including 1.1.3 [1].

Exploitation

An attacker with at least Contributor-level access (the lowest publishing role) can inject arbitrary JavaScript code through the vulnerable parameter [1]. The attack does not require any special network conditions beyond having the ability to modify a page via the plugin's settings or shortcodes [1].

Impact

Once stored, the injected script executes in the context of any user who views the affected page [1]. This can lead to session hijacking, defacement, or redirection to malicious sites, compromising the integrity of the WordPress installation [1].

Mitigation

Users should update to a patched version of the plugin as soon as it becomes available [1]. As of the publication date, no workaround is documented, and the vendor has not released a fix for this issue [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.