CVE-2025-62119
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ViitorCloud Technologies Pvt Ltd Add Featured Image Custom Link custom-url-to-featured-image allows DOM-Based XSS.This issue affects Add Featured Image Custom Link: from n/a through <= 2.0.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
DOM-based XSS in WordPress Add Featured Image Custom Link plugin (<=2.0.0) allows script injection via crafted user interaction.
The Add Featured Image Custom Link plugin for WordPress (versions <= 2.0.0) suffers from a DOM-based Cross-Site Scripting (XSS) vulnerability. The plugin fails to properly neutralize input during web page generation, enabling an attacker to inject malicious scripts that execute in the browser of a visiting user.[1]
Exploitation requires a privileged user (e.g., an administrator) to perform an action such as clicking a crafted link or visiting a specially prepared page. The attack is DOM-based, meaning the payload manipulates the Document Object Model on the client side without needing server-side reflection.[1]
A successful attack allows the injection of arbitrary HTML and JavaScript, which can be used to redirect visitors, display unwanted advertisements, steal session cookies, or deface the site. The CVSS score of 5.9 reflects a medium severity, but the potential for mass exploitation in automated campaigns is significant.[1]
Users are strongly advised to update the plugin to the latest available version as soon as possible. If an update is not yet available, consider temporarily deactivating the plugin or applying a virtual patch via a web application firewall. Hosting providers or web developers can assist with immediate mitigation steps.[1]
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <= 2.0.0
- Range: <=2.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.