CVE-2025-62984: WordPress WP AdCenter plugin <= 2.6.1 - Cross Site Scripting (XSS) vulnerability
Published Oct 27, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPeka WP AdCenter wpadcenter allows Stored XSS.This issue affects WP AdCenter: from n/a through <= 2.6.1.
Affected Software
2 affected components
WPEka WP AdCenter<=2.6.1
WordPress WP AdCenter<=2.6.1
Event History
Oct 27, 2025
CVE Published
via MITRE·01:34 AM
Data Sourced
via MITRE·01:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-62984?
CVE-2025-62984 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-62984?
To mitigate CVE-2025-62984, upgrade WP AdCenter to version 2.6.2 or later.
3
What software is impacted by CVE-2025-62984?
CVE-2025-62984 affects WPeka WP AdCenter versions up to and including 2.6.1.
4
What is Stored XSS in the context of CVE-2025-62984?
Stored XSS in CVE-2025-62984 allows an attacker to inject malicious scripts that are stored on the server and executed when users access compromised pages.
5
Can CVE-2025-62984 be exploited remotely?
Yes, CVE-2025-62984 can be exploited remotely if an attacker can craft input that gets stored and executed on the victim's web browser.