Stored XSS Vulnerability in WP Last Modified Info by Sayan Datta
CVE-2025-62968

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 October 2025

What is CVE-2025-62968?

The WP Last Modified Info plugin, developed by Sayan Datta, is susceptible to a stored cross-site scripting (XSS) vulnerability. This issue arises from improper handling of input during web page generation, allowing attackers to inject malicious scripts into the web pages viewed by users. When these scripts are executed, they can lead to unauthorized access to cookies, session tokens, or other sensitive information. Users are advised to update to the latest version to mitigate this risk and enhance overall website security.

Affected Version(s)

WP Last Modified Info <= n/a

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ | Patchstack Bug Bounty Program
.