Stored Cross-Site Scripting Vulnerability in Custom Post Type UI Plugin for WordPress
CVE-2025-14056
What is CVE-2025-14056?
The Custom Post Type UI plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping in the 'label' parameter during custom post type imports. This flaw allows authenticated attackers with Administrator privileges to insert malicious scripts. These scripts can execute on the Tools → Get Code page, potentially compromising users that access this functionality. Users should ensure they are running the patched version of the plugin to mitigate the risk associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Custom Post Type UI * <= 1.18.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved