
CVE-2025-7431
An authenticated attacker Administrator can exploit a Stored Cross-Site Scripting (XSS) vulnerability in the Knowledge Base plugin for WordPress by injecting malicious shortcode content into the plugin's settings.
WordPress Admin Dashboard → Knowledge Base → Settings
[kbalert type='" onmouseover="alert('hacked_by_nagisa_yumaa')"']XSS[/kbalert]
3. Trigger xss
When a victim (such as an administrator or any logged-in user) accesses the “All Articles” view of the Knowledge Base, the malicious JavaScript embedded in the slug is rendered and automatically executed, triggering the attack.

Persistent XSS leads to:
Session hijacking
Admin account takeover
Phishing within WordPress dashboard
The vulnerability affects all versions ≤ 2.3.1