Executive brief
The custom-post-edit WordPress plugin allows unauthenticated attackers to inject malicious JavaScript code that executes in the browsers of site visitors. An attacker can craft a malicious link and trick users into clicking it, enabling account hijacking, credential theft, or malware distribution to thousands of WordPress sites simultaneously.
Technical details
This vulnerability is a reflected Cross-Site Scripting (XSS) flaw in the custom-post-edit WordPress plugin through version 1.0.4, caused by improper neutralization of user input during web page generation. The vulnerability is accessible to unauthenticated attackers and requires user interaction (e.g., clicking a malicious link). Successful exploitation allows injection of arbitrary JavaScript that runs in the context of the victim's session, potentially leading to session hijacking, credential theft, or malware distribution. No official patch is currently available; Patchstack has issued a mitigation rule to block attacks.
Affected products
- Christopher Churchill custom-post-edit through 1.0.4
Timeline
- 2025-03-19: disclosed
- 2025-12-31: advisory