
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62997 is a Sensitive Data Exposure vulnerability (CWE-201: Insertion of Sensitive Information Into Sent Data) in the WP EasyCart WordPress plugin developed by levelfourdevelopment. It affects all versions of WP EasyCart up to and including 5.8.11, and was reported by researcher benzdeus on November 8, 2025, with public disclosure on December 8–9, 2025. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium), exploitable by unauthenticated remote attackers with no user interaction required (Patchstack).
The root cause is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data), meaning the plugin inadvertently includes sensitive data in responses or transmitted data that should not be accessible to unauthenticated users. The attack vector is network-based, requires no privileges or user interaction, and has low attack complexity — an unauthenticated attacker can retrieve embedded sensitive data by sending crafted requests to the affected plugin endpoints. This falls under OWASP Top 10 category A1: Broken Access Control, and the exploitation pattern aligns with CAPEC-12 (Choosing Message Identifier) and related data retrieval attack patterns (Patchstack).
Successful exploitation allows an unauthenticated attacker to view sensitive information that is normally restricted to privileged users, such as configuration data, internal application details, or customer/order-related data within the WP EasyCart e-commerce plugin. While the confidentiality impact is rated as low and there is no integrity or availability impact, the exposed data could be leveraged to facilitate further attacks against the WordPress site or its users. The vulnerability is particularly relevant to WooCommerce/e-commerce environments where customer or payment-adjacent data may be present (Patchstack).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2025-62997. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale, regardless of site popularity (Patchstack).
The vendor has released WP EasyCart version 5.8.12, which patches this vulnerability. All users running version 5.8.11 or earlier should update to 5.8.12 or later immediately. Patchstack users can enable auto-update for vulnerable plugins to receive protection automatically. If an immediate update is not possible, site owners should consult their hosting provider or web developer for assistance (Patchstack).
Patchstack, which coordinated the disclosure, classifies this as a low-priority vulnerability with unlikely exploitation impact. The vulnerability was credited to researcher benzdeus and disclosed through Patchstack's Vulnerability Disclosure Program (VDP). No notable broader media coverage or significant community discussion has been identified beyond the Patchstack advisory (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."