Stored Cross-Site Scripting Vulnerability in HT Script Plugin for WordPress
CVE-2025-12112

6.4MEDIUM

What is CVE-2025-12112?

The HT Script plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability found in all versions up to and including 1.1.6. This issue arises from insufficient capability checks, allowing authenticated users with Author privileges or higher to insert arbitrary scripts. When these scripts are accessed by a user, they are executed, potentially leading to unauthorized actions within the context of the user's session. This vulnerability emphasizes the importance of secure coding practices and adequate permission checks in plugins.

Affected Version(s)

Insert Headers and Footers Code – HT Script * <= 1.1.6

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn
.
CVE-2025-12112 : Stored Cross-Site Scripting Vulnerability in HT Script Plugin for WordPress