Stored XSS Vulnerability in Post List Featured Image Plugin by WordPress
CVE-2025-62937
5.4MEDIUM
What is CVE-2025-62937?
A stored cross-site scripting (XSS) vulnerability exists in the Post List Featured Image plugin, which allows attackers to inject malicious scripts. This vulnerability affects all versions of the plugin up to and including 0.5.9, potentially enabling attackers to execute arbitrary JavaScript in users' browsers. It can compromise website security and data integrity, leading to unauthorized actions and user information theft.
Affected Version(s)
Post List Featured Image <= n/a
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Muhammad Yudha - DJ | Patchstack Bug Bounty Program