CVE-2025-7431

MEDIUM

WordPress Knowledge Base <2.3.1 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-7431. PoCs published by NagisaYumaa.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2025-7431, a stored XSS vulnerability in the Knowledge Base WordPress plugin (versions ≤ 2.3.1). It includes steps to reproduce the exploit, payload examples, and impact analysis, but lacks functional exploit code.

Description

The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Exploits (1)

nomisec WRITEUP
by NagisaYumaa · poc
https://github.com/NagisaYumaa/CVE-2025-7431

This repository provides a detailed technical analysis of CVE-2025-7431, a stored XSS vulnerability in the Knowledge Base WordPress plugin (versions ≤ 2.3.1). It includes steps to reproduce the exploit, payload examples, and impact analysis, but lacks functional exploit code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Knowledge Base WordPress plugin ≤ 2.3.1
Auth required
Prerequisites: Authenticated access (Administrator+) to WordPress dashboard · Knowledge Base plugin installed and activated
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 4.4
EPSS 0.0025
EPSS Percentile 15.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
ajay/Knowledge Base < 2.3.1
Published Jul 18, 2025
Tracked Since Feb 18, 2026