
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62097 is a DOM-based Cross-Site Scripting (XSS) vulnerability in the SEO Slider WordPress plugin by SEOthemes, affecting all versions up to and including 1.1.1. The vulnerability stems from improper neutralization of input during web page generation (CWE-79), allowing authenticated attackers to inject malicious scripts into affected pages. It was reported by Muhammad Yudha - DJ on September 24, 2025, and publicly disclosed by Patchstack on December 31, 2025. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation) and manifests as a DOM-based XSS, meaning malicious payloads are processed and executed within the browser's DOM without necessarily being reflected from the server. Exploitation requires the attacker to hold at least a Contributor or Developer role on the WordPress site, and successful execution also requires a privileged user to perform an action such as clicking a malicious link or visiting a crafted page. The unsanitized input is injected during page generation and executed in the context of other users' browsers (Patchstack).
Successful exploitation allows an authenticated attacker to inject and execute arbitrary JavaScript in the browsers of other users visiting the affected WordPress site, potentially leading to session token theft, credential harvesting, unauthorized actions performed on behalf of victims, or defacement of site content. The scope is changed (S:C in CVSS), meaning the impact can extend beyond the vulnerable component to affect other users' sessions and data. Confidentiality, integrity, and availability are each assessed as Low impact, consistent with typical XSS exploitation scenarios (Patchstack, Red Hat CVE).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2025-62097. The EPSS score is approximately 0.034%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as low priority and notes it is unlikely to be exploited, though XSS vulnerabilities in WordPress plugins are sometimes leveraged in mass-exploit campaigns targeting large numbers of sites (Patchstack).
wp-content/plugins/seo-slider/ that may indicate tampering or webshell injection following XSS-based privilege escalation.As of the disclosure date (December 31, 2025), no official patch has been released by the plugin vendor for the SEO Slider plugin. Site administrators should consider deactivating and removing the SEO Slider plugin until a patched version is available. As a compensating control, restrict Contributor and Developer role assignments to trusted users only, and consider deploying a Web Application Firewall (WAF) or a security plugin such as Patchstack to virtually patch the vulnerability (Patchstack).
Patchstack, which discovered and disclosed the vulnerability, classifies it as low priority with no impactful threat, noting it is unlikely to be exploited in targeted attacks. The vulnerability was reported through Patchstack's vulnerability disclosure program by researcher Muhammad Yudha - DJ. No significant broader media coverage or notable community commentary has been identified beyond standard vulnerability database aggregation (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."