Home/Research/CVEs/CVE-2025-12163 | Stored XSS in OmniPress Plugin

CVE-2025-12163 | Stored XSS in OmniPress Plugin

CVE-2025-12163: Stored XSS in OmniPress WordPress plugin via author-level access. CVSS 6.4. Full technical analysis, PoC, and remediation by Kai Aizen.

TL;DR
This vulnerability has been assigned CVE-2025-12163 and is currently pending full publication details from the National Vulnerability Database (NVD). The vulnerability was discovered and responsibly disclosed by Kai Aizen (SnailSploit).
CVE Disclosures →

Status

This vulnerability has been assigned CVE-2025-12163 and is currently pending full publication details from the National Vulnerability Database (NVD). The vulnerability was discovered and responsibly disclosed by Kai Aizen (SnailSploit).

Description

Full technical details will be published once the vulnerability information is released by NVD and the affected software vendor has had adequate time to patch and notify users.

Timeline

  • Discovery: Vulnerability discovered during WordPress plugin security assessment
  • Disclosure: Responsibly disclosed to plugin developer
  • CVE Assignment: CVE-2025-12163 assigned
  • Status: Awaiting NVD publication

Updates

This page will be updated with complete technical details, proof of concept, and remediation guidance once the information is publicly available through NVD.

For the most current information, check the official NVD entry or contact [email protected].

References

Discovered by: Kai Aizen (SnailSploit)

cite this work
BibTeX
@misc{aizen2026cve,
  author = {Aizen, Kai},
  title  = {CVE-2025-12163 | Stored XSS in OmniPress Plugin},
  year   = {2026},
  url    = {https://snailsploit.com/security-research/cves/cve-2025-12163/},
  note   = {snailsploit.com}
}
APA

Aizen, K. (2026). CVE-2025-12163 | Stored XSS in OmniPress Plugin. snailsploit.com. https://snailsploit.com/security-research/cves/cve-2025-12163/

MLA

Aizen, Kai. "CVE-2025-12163 | Stored XSS in OmniPress Plugin." snailsploit, 2026, https://snailsploit.com/security-research/cves/cve-2025-12163/.

Chicago

Aizen, Kai. "CVE-2025-12163 | Stored XSS in OmniPress Plugin." snailsploit (blog). 2026. https://snailsploit.com/security-research/cves/cve-2025-12163/.

Permalink: https://snailsploit.com/security-research/cves/cve-2025-12163/
disclosure context
all disclosures
CVE Ledger →
23 published CVEs across container, web, OSS, kernel
advisories
GHSA disclosures →
coordinated security advisories
engage
Pen Testing →
same methodology, your stack
Author
Kai Aizen
Independent offensive security researcher. 23 published CVEs, 5 Linux kernel mainline patches, creator of AATMF / P.R.O.M.P.T / SEF, author of Adversarial Minds.