LiveActive security incident?Get immediate response
CVE Record

CVE-2025-53234: WordPress UDesign Core plugin <= 4.14.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AndonDesign UDesign Core u-design-core allows Reflected XSS.This issue affects UDesign Core: from n/a through <= 4.14.0.

HighCVSS 7.1Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A WordPress add-on called UDesign Core has a flaw in versions 4.14.0 and earlier that lets attackers craft a malicious link. If a site administrator or visitor clicks it, attacker-controlled code can run in their browser, potentially stealing their session or tricking them into harmful actions on the site.

Executive priority

Schedule remediation within standard patch cycle. High CVSS but requires user interaction and no confirmed active exploitation; prioritize sites handling sensitive admin sessions.

Technical view

CVE-2025-53234 is a reflected cross-site scripting flaw (CWE-79) in the AndonDesign UDesign Core WordPress plugin through version 4.14.0. Improper neutralization of user-supplied input during page generation allows attacker-controlled script to execute in a victim's browser when they follow a crafted URL. CVSS 3.1 score is 7.1 with scope change and low confidentiality, integrity, and availability impact.

Likely exposure

WordPress sites running the AndonDesign UDesign Core plugin (u-design-core) at version 4.14.0 or earlier are exposed. Risk is highest for public-facing sites whose administrators or editors can be socially engineered into clicking attacker-supplied links while authenticated to the WordPress admin area.

Exploitation context

No evidence of active exploitation in the cited sources, and the CVE is not listed in CISA KEV. Reflected XSS typically requires luring an authenticated user, often an administrator, to click a crafted link. Patchstack catalogs the issue but no public proof-of-concept or in-the-wild campaign is referenced in the bundle.

Researcher notes

CWE-79 reflected XSS with CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L scoring 7.1. Scope change indicates the injected script can affect resources beyond the vulnerable component, consistent with reflected XSS executing in an authenticated admin context. The Patchstack advisory is the primary reference; specific vulnerable parameter and patched version are not detailed in the supplied bundle, so consult Patchstack and the vendor for technical specifics before validation.

Mitigation direction

  • Update UDesign Core to a fixed release once published by AndonDesign; check Patchstack and the vendor for guidance.
  • If no patch is yet available, deactivate UDesign Core or restrict plugin features until a fix ships.
  • Apply WAF rules that block common reflected XSS payload patterns reaching plugin endpoints.
  • Train administrators and editors to avoid clicking unverified links while logged into WordPress.
  • Enforce least-privilege roles so fewer accounts can be targeted with high-impact session theft.

Validation and detection

  • Inventory WordPress sites and identify any running UDesign Core (u-design-core) at version 4.14.0 or earlier.
  • Review the Patchstack advisory to confirm the affected parameter and any vendor-issued fixed version.
  • Check WordPress plugin update screens and vendor channels for an official patched release.
  • Inspect web server and WAF logs for suspicious query strings targeting UDesign Core endpoints.
  • After patching, verify the plugin version on each site and confirm no rollback occurred.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-79: User-session and phishing behavior lookup

Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2025-53234 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.1 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.1CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L2.83.7Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

7.1High
CVSS 3.1 vector shape for CVE-2025-53234Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
AndonDesignUDesign Coreu-design-core, 0unaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-79 · source CWE mapping

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.