CVE-2025-12904
HIGHSNORDIAN's H5PxAPIkatchu <= 0.4.17 - Unauthenticated Stored Cross-Site Scripting via insert_data AJAX Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-12904. PoCs published by MooseLoveti.
AI-analyzed exploit summary This repository provides a detailed writeup and proof-of-concept for CVE-2025-12904, an unauthenticated stored XSS vulnerability in SNORDIAN's H5PxAPIkatchu WordPress plugin. The vulnerability allows an attacker to inject malicious scripts via the insert_data action, which are then executed in the admin interface.
Description
The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJAX endpoint in all versions up to, and including, 0.4.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Exploits (1)
This repository provides a detailed writeup and proof-of-concept for CVE-2025-12904, an unauthenticated stored XSS vulnerability in SNORDIAN's H5PxAPIkatchu WordPress plugin. The vulnerability allows an attacker to inject malicious scripts via the insert_data action, which are then executed in the admin interface.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N