Junglewise Threat Intelligence

CVE-2025-62989: Gora Tech Cooked stored cross-site scripting

CVE-2025-62989 · Severity: medium · CVSS 5.9 · Published 2025-12-31

Executive brief

Cooked is a WordPress plugin for recipe management and content creation. A stored cross-site scripting (XSS) vulnerability in versions up to 1.11.3 allows authenticated administrators or developers to inject malicious scripts that persist on the site and execute in the browsers of other users, potentially stealing credentials or hijacking accounts.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in the Cooked WordPress plugin that fails to properly neutralize user input during web page generation. The vulnerability affects versions 1.11.3 and earlier. Exploitation requires authenticated privileges (administrator or developer role) and user interaction (e.g., clicking a malicious link or visiting a crafted page). Successful exploitation allows an attacker to inject persistent JavaScript code that executes in the browsers of site visitors, potentially stealing session data, credentials, or performing actions on their behalf. A patch is available in version 1.11.4 and later.

Affected products

  • Gora Tech Cooked <=1.11.3

Timeline

  • 2025-10-11: disclosed: Reported to Patchstack
  • 2025-12-31: advisory: Published by Patchstack
  • 2025-12-31: patched: Fixed in version 1.11.4

References

Related threats