
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62959 is a Remote Code Execution (RCE) vulnerability caused by improper control of code generation (Code Injection) in the VideoWhisper Paid Videochat Turnkey Site WordPress plugin (slug: ppv-live-webcams). It allows Remote Code Inclusion by authenticated attackers with Administrator-level privileges. All plugin versions up to and including 7.3.23 are affected; version 7.3.24 contains the fix. The vulnerability was reported by researcher Luciano Hanna on September 16, 2025, and published by Patchstack on October 16, 2025. It carries a CVSS v3.1 base score of 9.1 (Critical) (Patchstack).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), specifically enabling Remote Code Inclusion. An attacker with Administrator-level access can supply a malicious remote file path or URL that the plugin includes and executes server-side, effectively allowing arbitrary PHP or system code to run within the application's context. The attack vector is network-based, requires no user interaction, and has low attack complexity, though it does require high privileges (Administrator role). The scope is changed, meaning the impact can extend beyond the vulnerable component itself (Patchstack).
Successful exploitation grants an attacker the ability to execute arbitrary remote code on the underlying web server, potentially leading to complete system compromise. Consequences include unauthorized access to sensitive data, installation of backdoors or web shells, manipulation of site content, and lateral movement to other systems on the same hosting environment. Because the scope is marked as "Changed" in the CVSS vector, the impact can extend beyond the WordPress application itself to the broader server infrastructure (Patchstack).
As of the time of publication, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Patchstack). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.029% (0.000290), indicating a low current probability of exploitation in the wild. Exploitation requires Administrator-level credentials, which significantly limits the attack surface compared to unauthenticated vulnerabilities, though Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns.
ppv-live-webcams (Paid Videochat Turnkey Site) plugin at version 7.3.23 or earlier using tools like WPScan, Shodan, or by inspecting plugin readme files exposed at /wp-content/plugins/ppv-live-webcams/readme.txt..php files; unexpected DNS lookups from the WordPress server process./wp-content/plugins/ppv-live-webcams/ or other writable directories; presence of web shells (e.g., files containing eval, base64_decode, system, passthru, or shell_exec).allow_url_include warnings; web server logs showing requests to plugin settings pages from unfamiliar IP addresses.bash, curl, wget, python) with unusual arguments or connecting to external hosts.The vendor VideoWhisper has released version 7.3.24 of the Paid Videochat Turnkey Site plugin, which resolves this vulnerability. Site administrators should update the plugin immediately via the WordPress admin dashboard or by downloading the patched version from the WordPress plugin repository. If an immediate update is not possible, restrict Administrator access to trusted users only, enforce strong authentication (including MFA), and consider temporarily deactivating the plugin. Additionally, ensure the PHP allow_url_include directive is disabled in php.ini as a defense-in-depth measure against remote file inclusion attacks (Patchstack).
The vulnerability was noted in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of October 13–19, 2025, and picked up by several vulnerability aggregation platforms including Vulners, VulDB, and radar.offseq.com shortly after publication. Community reaction has been limited given the high privilege requirement, with Patchstack classifying the exploitability risk as "Low priority" despite the high CVSS score. No significant vendor statements or notable researcher commentary beyond the initial Patchstack disclosure have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."