CVE-2025-12904

HIGH

SNORDIAN's H5PxAPIkatchu <= 0.4.17 - Unauthenticated Stored Cross-Site Scripting via insert_data AJAX Endpoint

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-12904. PoCs published by MooseLoveti.

AI-analyzed exploit summary This repository provides a detailed writeup and proof-of-concept for CVE-2025-12904, an unauthenticated stored XSS vulnerability in SNORDIAN's H5PxAPIkatchu WordPress plugin. The vulnerability allows an attacker to inject malicious scripts via the insert_data action, which are then executed in the admin interface.

Description

The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJAX endpoint in all versions up to, and including, 0.4.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Exploits (1)

nomisec WRITEUP
by MooseLoveti · poc
https://github.com/MooseLoveti/SNORDIAN-s-H5PxAPIkatchu-CVE-Report

This repository provides a detailed writeup and proof-of-concept for CVE-2025-12904, an unauthenticated stored XSS vulnerability in SNORDIAN's H5PxAPIkatchu WordPress plugin. The vulnerability allows an attacker to inject malicious scripts via the insert_data action, which are then executed in the admin interface.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: SNORDIAN's H5PxAPIkatchu <= 0.4.16
No auth needed
Prerequisites: Access to the WordPress admin-ajax.php endpoint · Valid ID within the object to avoid failure
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 7.2
EPSS 0.0025
EPSS Percentile 16.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
otacke/SNORDIAN's H5PxAPIkatchu < 0.4.17
Published Nov 14, 2025
Tracked Since Feb 18, 2026