CVE-2025-62907: Aviplugins.com Custom Post Type Attachment
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Custom Post Type Attachment custom-post-type-pdf-attachment allows Stored XSS.This issue affects Custom Post Type Attachment: from n/a through <= 3.4.6.
Affected products
- Aviplugins.com Custom Post Type Attachment: up to and including 3.4.6
Published 2025-10-27. Last modified 2026-10-08.