๐Ÿ” CVE Alert

CVE-2025-62907

MEDIUM 5.4

WordPress Custom Post Type Attachment plugin <= 3.4.6 - Cross Site Scripting (XSS) vulnerability

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Custom Post Type Attachment custom-post-type-pdf-attachment allows Stored XSS.This issue affects Custom Post Type Attachment: from n/a through <= 3.4.6.

CWE CWE-79
Vendor aviplugins.com
Product custom post type attachment
Published Oct 27, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for aviplugins.com custom post type attachment

Be the first to know when new medium vulnerabilities affecting aviplugins.com custom post type attachment are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

aviplugins.com / Custom Post Type Attachment
0 โ‰ค 3.4.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/custom-post-type-pdf-attachment/vulnerability/wordpress-custom-post-type-attachment-plugin-3-4-6-cross-site-scripting-xss-vulnerability?_s_id=cve

Credits

Muhammad Yudha - DJ | Patchstack Bug Bounty Program