Stored Cross-Site Scripting Vulnerability in HT Script Plugin for WordPress
CVE-2025-12112
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 November 2025
What is CVE-2025-12112?
The HT Script plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability found in all versions up to and including 1.1.6. This issue arises from insufficient capability checks, allowing authenticated users with Author privileges or higher to insert arbitrary scripts. When these scripts are accessed by a user, they are executed, potentially leading to unauthorized actions within the context of the user's session. This vulnerability emphasizes the importance of secure coding practices and adequate permission checks in plugins.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Insert Headers and Footers Code β HT Script * <= 1.1.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved