Stored XSS Vulnerability in Post List Featured Image Plugin by WordPress
CVE-2025-62937

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 October 2025

What is CVE-2025-62937?

A stored cross-site scripting (XSS) vulnerability exists in the Post List Featured Image plugin, which allows attackers to inject malicious scripts. This vulnerability affects all versions of the plugin up to and including 0.5.9, potentially enabling attackers to execute arbitrary JavaScript in users' browsers. It can compromise website security and data integrity, leading to unauthorized actions and user information theft.

Affected Version(s)

Post List Featured Image <= n/a

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ | Patchstack Bug Bounty Program
.