CVE-2025-14554

7.2 HIGH
Published: January 31, 2026 Modified: February 03, 2026
View on NVD

Description

The Sell BTC - Cryptocurrency Selling Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'orderform_data' AJAX action in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in order records that will execute whenever an administrator accesses the Orders page in the admin dashboard. The vulnerability was partially patched in version 1.5.

AI Explanation

### 1. Plain-Language Summary The Sell BTC WordPress plugin allows unauthenticated attackers to inject malicious code into order records. When an admin views the Orders page in their dashboard, this code runs automatically, enabling session hijacking or unauthorized actions. ### 2. Who Is Affected - **Product**: Sell BTC - Cryptocurrency Selling Calculator plugin for WordPress. - **Affected Versions**: All versions up to **1.5**. Version 1.5 has a **partial patch**, meaning it may still be vulnerable. ### 3. Attacker Exploitation Impact - Injects persistent malicious scripts (e.g., JavaScript) into order data. - Executes when admins view the Orders page, enabling: - Theft of admin session cookies (full account takeover). - Unauthorized admin actions (e.g., modifying settings, adding users). - Defacement or malware distribution via the compromised admin panel. ### 4. Recommended Remediation Steps 1. **Immediate Update**: Upgrade to a version **newer than 1.5** once fully patched (monitor plugin vendor releases). If unavailable, disable the plugin. 2. **Temporary Mitigations**: - Restrict admin dashboard access to trusted IPs (e.g., via `.ht

Generated: 2026-02-01 00:18

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Quick Stats

CVSS v3 Score
7.2 / 10.0
EPSS (Exploit Probability)
0.1%
19th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)