VYPR
Medium severity6.5NVD Advisory· Published Oct 27, 2025· Updated Apr 27, 2026

CVE-2025-62907

CVE-2025-62907

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Custom Post Type Attachment custom-post-type-pdf-attachment allows Stored XSS.This issue affects Custom Post Type Attachment: from n/a through <= 3.4.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in WordPress Custom Post Type Attachment plugin <=3.4.6 allows unauthenticated attackers to inject malicious scripts via unsanitized input.

The WordPress Custom Post Type Attachment plugin (versions up to and including 3.4.6) suffers from a vulnerability where user-supplied input is not properly neutralized during web page generation. This leads to a Stored Cross-Site Scripting (XSS) condition [1].

Attackers with contributor-level access or higher can inject arbitrary JavaScript into posts or pages that use the plugin's custom post type attachment functionality. The injected script persists in the database and automatically executes when any visitor views the affected page. No additional user interaction is required beyond the initial injection [1].

Successful exploitation allows an attacker to perform actions such as redirecting victims to malicious sites, injecting ads or phishing forms, or stealing session cookies and other sensitive data. Because the attack is stored, it can affect every visitor who loads the compromised content [1].

The vulnerability is present in all versions up to 3.4.6. Users are strongly advised to update the plugin immediately. As a temporary mitigation, restrict contributor roles and review any custom post type attachment inputs for malicious content [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.