CVE-2025-62968 Overview
CVE-2025-62968 is a stored Cross-Site Scripting (XSS) vulnerability in the Sayan Datta WP Last Modified Info WordPress plugin. The flaw affects all plugin versions up to and including 1.9.2. Attackers with low-privileged authenticated access can inject malicious scripts that persist in the WordPress database. When administrators or other users load affected pages, the injected payload executes in their browser context.
The vulnerability is classified under CWE-79, Improper Neutralization of Input During Web Page Generation. The attack requires user interaction and can cross privilege boundaries, resulting in a scope change.
Critical Impact
Authenticated attackers can inject persistent JavaScript payloads that execute in the context of higher-privileged WordPress users, enabling session theft, administrative account takeover, or malicious redirects.
Affected Products
- WP Last Modified Info plugin versions up to and including 1.9.2
- WordPress installations running the Sayan Datta WP Last Modified Info plugin
- Sites where low-privileged authenticated users can access plugin functionality
Discovery Timeline
- 2025-10-27 - CVE-2025-62968 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-62968
Vulnerability Analysis
The WP Last Modified Info plugin fails to properly neutralize user-supplied input before rendering it in web pages. An authenticated attacker with low privileges can submit crafted input containing HTML or JavaScript. The plugin stores this input without adequate sanitization or output encoding.
When a victim loads a page that displays the stored data, the browser interprets the payload as active script content. Because the vulnerability produces a scope change, the injected script can affect users at higher trust levels than the attacker. This includes administrators who visit affected admin pages or front-end views.
Root Cause
The root cause is insufficient input validation and output escaping within the plugin's data handling routines. The plugin does not apply WordPress sanitization functions such as sanitize_text_field() on input or esc_html() and esc_attr() on output. This allows raw markup to reach the rendered DOM.
Attack Vector
Exploitation requires network access to the WordPress site and authenticated access at a low privilege tier. The attacker submits a payload containing script tags or event handlers through an affected plugin input field. Once stored, the payload triggers when any user views the rendered content, satisfying the user interaction requirement.
Technical details are documented in the Patchstack XSS Vulnerability Report. No proof-of-concept exploit code is publicly available in verified repositories.
Detection Methods for CVE-2025-62968
Indicators of Compromise
- Unexpected <script> tags, javascript: URIs, or DOM event handlers such as onerror and onload stored in wp_postmeta or wp_options entries related to the plugin
- Administrator sessions exhibiting unexpected outbound requests or unauthorized account creation shortly after viewing plugin-rendered content
- Browser Content Security Policy (CSP) violation reports originating from WordPress admin pages
Detection Strategies
- Audit WordPress database tables for stored payloads containing HTML tags or JavaScript event handlers submitted through plugin input fields
- Review web server access logs for POST requests to plugin endpoints originating from low-privileged user accounts
- Deploy a Web Application Firewall (WAF) rule set that flags XSS patterns targeting WordPress plugin routes
Monitoring Recommendations
- Monitor WordPress user role changes and new administrator account creation events
- Alert on modifications to plugin-related database entries by non-administrator users
- Track outbound HTTP requests from browsers loading WordPress admin pages to identify data exfiltration attempts
How to Mitigate CVE-2025-62968
Immediate Actions Required
- Identify all WordPress instances running WP Last Modified Info version 1.9.2 or earlier
- Restrict plugin access to trusted authenticated users until a patch is applied
- Review recent plugin-related database entries for injected script content and remove malicious payloads
- Rotate credentials for any administrator account that may have loaded compromised pages
Patch Information
At the time of publication, the advisory lists affected versions from n/a through 1.9.2. Site operators should monitor the Patchstack advisory and the WordPress plugin repository for a fixed release, and upgrade as soon as a patched version becomes available.
Workarounds
- Deactivate and remove the WP Last Modified Info plugin until an updated version is released
- Restrict contributor and author role assignments to trusted users to reduce the attacker pool
- Deploy a WAF configured to strip or block script tags and event handlers in requests to WordPress admin endpoints
- Enforce a strict Content Security Policy on WordPress admin pages to limit the impact of injected scripts
# Example: disable the vulnerable plugin via WP-CLI
wp plugin deactivate wp-last-modified-info
wp plugin delete wp-last-modified-info
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.