CVE-2025-62997
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-62997 is a Sensitive Data Exposure vulnerability (CWE-201: Insertion of Sensitive Information Into Sent Data) in the WP EasyCart WordPress plugin developed by levelfourdevelopment. It affects all versions of WP EasyCart up to and including 5.8.11, and was reported by researcher benzdeus on November 8, 2025, with public disclosure on December 8–9, 2025. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium), exploitable by unauthenticated remote attackers with no user interaction required (Patchstack).

Technical details

The root cause is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data), meaning the plugin inadvertently includes sensitive data in responses or transmitted data that should not be accessible to unauthenticated users. The attack vector is network-based, requires no privileges or user interaction, and has low attack complexity — an unauthenticated attacker can retrieve embedded sensitive data by sending crafted requests to the affected plugin endpoints. This falls under OWASP Top 10 category A1: Broken Access Control, and the exploitation pattern aligns with CAPEC-12 (Choosing Message Identifier) and related data retrieval attack patterns (Patchstack).

Impact

Successful exploitation allows an unauthenticated attacker to view sensitive information that is normally restricted to privileged users, such as configuration data, internal application details, or customer/order-related data within the WP EasyCart e-commerce plugin. While the confidentiality impact is rated as low and there is no integrity or availability impact, the exposed data could be leveraged to facilitate further attacks against the WordPress site or its users. The vulnerability is particularly relevant to WooCommerce/e-commerce environments where customer or payment-adjacent data may be present (Patchstack).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2025-62997. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale, regardless of site popularity (Patchstack).

Mitigation and workarounds

The vendor has released WP EasyCart version 5.8.12, which patches this vulnerability. All users running version 5.8.11 or earlier should update to 5.8.12 or later immediately. Patchstack users can enable auto-update for vulnerable plugins to receive protection automatically. If an immediate update is not possible, site owners should consult their hosting provider or web developer for assistance (Patchstack).

Community reactions

Patchstack, which coordinated the disclosure, classifies this as a low-priority vulnerability with unlikely exploitation impact. The vulnerability was credited to researcher benzdeus and disclosed through Patchstack's Vulnerability Disclosure Program (VDP). No notable broader media coverage or significant community discussion has been identified beyond the Patchstack advisory (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management