VYPR
Medium severity6.5NVD Advisory· Published Oct 27, 2025· Updated Apr 27, 2026

CVE-2025-62905

CVE-2025-62905

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Query Posts query-posts allows Stored XSS.This issue affects Query Posts: from n/a through <= 0.3.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS vulnerability in Query Posts WordPress plugin (≤0.3.2) allows authenticated attackers to inject malicious scripts, risking site compromise.

The Query Posts WordPress plugin version 0.3.2 and earlier suffers from a stored cross-site scripting (XSS) vulnerability due to improper neutralization of user input during web page generation [1]. This flaw enables an attacker to inject arbitrary HTML and JavaScript code that persists on the affected site.

Exploitation requires a privileged user action, such as clicking a malicious link or submitting a crafted form, but does not require authentication of the attacker themselves. Once triggered, the injected payload executes in the context of any visitor's browser [1].

Successful exploitation allows the attacker to perform actions like redirecting users, displaying advertisements, or injecting other malicious payloads. The vulnerability is noted to be used in mass-exploit campaigns targeting thousands of websites [1].

As immediate mitigation, users should update the Query Posts plugin to a patched version. If updating is not possible, contacting a hosting provider or web developer for assistance is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.