Cross-site Scripting Vulnerability in Simple Payment by Ido Kobelkowsky
CVE-2025-62076

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 November 2025

What is CVE-2025-62076?

The Simple Payment plugin for WordPress, developed by Ido Kobelkowsky, has a vulnerability that allows for improper neutralization of input during web page generation, leading to potential Cross-site Scripting (XSS) attacks. This vulnerability affects versions up to 2.4.6 of the plugin, allowing malicious users to inject arbitrary web scripts into pages viewed by other users. This can lead to unauthorized actions, data theft, and compromise of user sessions. Ensuring your plugins are updated and implementing best security practices is essential to mitigate such risks.

Affected Version(s)

Simple Payment <= n/a

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien | Patchstack Bug Bounty Program
.
CVE-2025-62076 : Cross-site Scripting Vulnerability in Simple Payment by Ido Kobelkowsky