Junglewise Threat Intelligence

CVE-2025-49355: ikaes Accessibility Press stored cross-site scripting

CVE-2025-49355 · Severity: medium · CVSS 5.9 · Published 2025-12-31

Executive brief

Accessibility Press is a WordPress plugin that helps websites be more accessible to users with disabilities. A vulnerability allows administrators or developers to inadvertently inject malicious scripts into the site, which could be stored and executed for all visitors—potentially stealing login credentials, hijacking user accounts, or redirecting visitors to malicious sites.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in the input validation logic of Accessibility Press versions up to 1.0.2. The plugin fails to properly sanitize or escape user-supplied input during web page generation, allowing an attacker with administrator or developer privileges to inject malicious JavaScript that persists in the database. When other users (including visitors) view the affected page, the malicious script executes in their browser context. Exploitation requires a privileged user to perform an action such as clicking a malicious link or submitting a crafted form. No official patch is currently available; affected sites should upgrade to a patched version or disable the plugin.

Affected products

  • ikaes Accessibility Press through 1.0.2

Timeline

  • 2025-09-30: disclosed: Reported by HunSec
  • 2025-12-31: advisory: Published by Patchstack and registered as CVE-2025-49355

References