
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62042 is a Cross-Site Scripting (XSS) vulnerability in the WordPress "Event post" plugin by Bastien Ho, affecting all versions up to and including 5.10.3. The vulnerability was reported by Muhammad Yudha - DJ on September 13, 2025, and publicly disclosed on October 16–22, 2025 via Patchstack. It carries a CVSS v3.1 base score of 6.5 (Medium), assigned by CISA-ADP (Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), indicating that user-supplied input is not properly sanitized or escaped before being rendered in web pages. Exploitation requires the attacker to hold at least a Contributor or Developer-level WordPress role and also requires a privileged user to perform an action (e.g., view a crafted page), making this a stored or reflected XSS with user interaction. The attack vector is network-based with low complexity, and the scope is changed, meaning the injected script can affect the browser context of other users visiting the site (Patchstack).
Successful exploitation allows an attacker to inject malicious scripts — such as redirects, advertisements, credential-harvesting forms, or other HTML payloads — into WordPress pages served to site visitors. The confidentiality, integrity, and availability impacts are each rated Low, but the changed scope means the attack can affect users beyond the attacker's own session. In a worst-case scenario, injected scripts could be used to steal session cookies, perform actions on behalf of authenticated users, or redirect visitors to malicious sites (Patchstack).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-62042. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack rates this as low priority and notes it is unlikely to be exploited, though XSS vulnerabilities in WordPress plugins are sometimes leveraged in mass-exploit campaigns targeting large numbers of sites (Patchstack).
The vulnerability is patched in Event post version 5.10.4. Site administrators should update the plugin to version 5.10.4 or later immediately. If an immediate update is not possible, consider temporarily deactivating the plugin or restricting Contributor/Developer role access until the update can be applied. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard (Patchstack).
Wordfence included this vulnerability in their weekly WordPress vulnerability report covering October 13–19, 2025, providing broader community visibility (Wordfence). No significant additional vendor statements or notable researcher commentary beyond the Patchstack disclosure have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."