s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2025-30975

📛 CVE Title

WordPress Add Custom Codes <= 4.80 - Arbitrary Code Execution vulnerability

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Code Injection.This issue affects Add Custom Codes: from n/a through <= 4.80.

Overview

State
PUBLISHED
Assigner (CNA)
Patchstack
CVSS severity
HIGH
CVSS score
CVSS 7.5 / 10 7.5 7.5 / 10
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Effective score
7.5 / 10 HIGH source: CNA overview
CWE(s)
CWE-94
Reserved
2025-03-26
Published
2025-08-20 10:03 UTC
Last updated
2026-04-28 18:12 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/30xxx/CVE-2025-30975.json
Linked Threat
CVE-2025-30975 — Add Custom Codes <= 4.80 - Authenticated (Contributor+) Remote Code Execution

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2025-08-20 08:15:29 UTC
NVD last modified
2026-06-17 09:09:40 UTC
NVD CVSS v3.1
CVSS 7.5 / 10 7.5 7.5 / 10 HIGH source: audit@patchstack.com
NVD CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability subscore
1.6 / 10
Impact subscore
5.9 / 10
EPSS score
0.0033 (probability of exploitation in next 30 days)
EPSS percentile
25.19% vs all CVEs — higher = more likely to be exploited, as of 2026-06-30

NVD / KEV / EPSS data refreshed 2026-07-01 00:28 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2025-25299
Assigner
Patchstack
Published
Aug 20, 2025, 8:03:47 AM
Updated
Apr 28, 2026, 4:12:02 PM
EUVD base score (CVSS 3.1)
7.5 / 10
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EUVD-reported EPSS
0.0700
Vendors
SaifuMak
Products
Add Custom Codes (0 ≤4.80)
Add Custom Codes (n/a ≤4.80)
Aliases
GHSA-29cf-7968-4gr3

ENISA description: Improper Control of Generation of Code ('Code Injection') vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Code Injection.This issue affects Add Custom Codes: from n/a through <= 4.80.

EUVD references (1)

Affected products (1)

VendorProductVersionsPlatforms
SaifuMak Add Custom Codes 0 (affected)

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

MITRE references (1) cveawg.mitre.org

Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.

Web references (5)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (1)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Indicators (2)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
domain injection.this no local data 2026-05-18 21:19 UTC
cve CVE-2025-30975 no local data 2026-06-06 13:35 UTC

Flagged vendors

    Remediations (19)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • Wordfence remediation: Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript
      Wordfence

      Update to version 5.0, or a newer patched version

      2026-06-06 13:35 UTC
    • web:blog.qualys.com

      EVALUATE Vendor-Suggested Mitigation with Policy Audit With Qualys Policy Audit's Out-of-the-Box Mitigation or Compensatory Controls, reduce the risk of a vulnerability being exploited because the remediation ( fix / patch ) cannot be done now; these security controls are not recommended by any industry standards, such as CIS, DISA-STIG.

      2026-05-22 13:10 UTC
    • web:krebsonsecurity.com

      October's Patch Tuesday also marks the final month that Microsoft will ship security updates for Windows 10 systems.

      2026-05-22 13:10 UTC
    • web:support.microsoft.com

      This out-of-band update for Windows 11, version 25H2 and 24H2 (KB5085518) includes fixes and improvements. To learn more about differences between security updates, optional non-security preview updates, out-of-band (OOB) updates, and continuous innovation, see Windows monthly updates explained. For information on Windows update terminology, see the different types of Windows software updates ...

      2026-05-22 13:10 UTC
    • web:securityaffairs.com

      They just needed to be patient — and wait for someone to forget to patch . That is essentially the story behind CVE - 2025 -32975, a critical vulnerability in Quest KACE Systems Management Appliance, a tool used by IT teams across thousands of organizations to manage software, push patches, and control endpoints from a single console.

      2026-05-22 13:10 UTC
    • web:vulert.com

      Hackers are exploiting CVE - 2025 -32975, a critical Quest KACE SMA authentication bypass flaw with CVSS 10.0, allowing admin takeover of unpatched systems.

      2026-05-22 13:10 UTC
    • web:www.neowin.net

      Microsoft has released Patch Tuesday updates for Windows 11 KB5074109, KB5073455 for January 2026. Here's what's included.

      2026-05-22 13:10 UTC
    • web:www.techrepublic.com

      Microsoft's April 2026 Patch Tuesday fixes 165 vulnerabilities, including two zero-days, in one of the company's largest monthly security updates.

      2026-05-22 13:10 UTC
    • web:zecurit.com

      Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .

      2026-05-22 13:10 UTC
    • web:betanews.com

      Another month, another update for Windows which is problematic. This time around, it is the May 2026 Windows 11 security update - or the KB5089549 update.

      2026-05-22 03:53 UTC
    • web:www.romhacking.net

      Add temporary header() Patch file: Apply patch Original ROM: Modified ROM: Patch type: IPS BPS PPF UPS APS RUP Create patch Settings Rom Patcher JS v2.9 by Marc Robledo See on GitHub Donate Language English Français Deutsch Italiano Español Nederlands Svenska Català Valencià Português Brasileiro Russian 日本語 中文(简体) 中文 ...

      2026-05-22 03:53 UTC
    • web:www.fixferreterias.com

      FIX FERRETERÍAS Acerca de nosotros Ubica tu tienda Catálogo Grupo Truper SOPORTE AL CLIENTE Facturación Cotizaciones Preguntas Frecuentes Mis pedidos POLÍTICAS Ventas Devoluciones Garantías Precios Aviso de privacidad

      2026-05-22 03:53 UTC
    • web:www.linkedin.com

      Microsoft Security Response Center has issued an emergency mitigation for a newly disclosed BitLocker bypass vulnerability known as "YellowKey," after security researchers publicly released ...

      2026-05-22 03:53 UTC
    • web:hunt.io

      The flaw allows an unauthenticated, network-reachable attacker to impersonate legitimate users, including administrators, without supplying any credentials. Ten months after Quest published a patch , active exploitation of CVE - 2025 -32975 was observed in customer environments, with internet-exposed instances still running vulnerable versions.

      2026-05-22 03:53 UTC
    • web:learn.microsoft.com

      June 2025 Security Updates **This release consists of the following 66 Microsoft CVEs:**Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? **Mitigations?**Windows Storage Management Provider CVE - 2025 -24065Windows Storage Management Provider…

      2026-05-22 03:53 UTC
    • web:nvd.nist.gov

      An official website of the United States government NVD MENU

      2026-05-22 03:53 UTC
    • web:patch.com

      The best breaking news, stories, and events from the Patch network of local news sites

      2026-05-22 03:53 UTC
    • web:patch.moe

      Age Verification Are you 18 years or older? YES NO

      2026-05-22 03:53 UTC
    • web:www.pcworld.com

      PCWorld reports Microsoft released 167 security fixes in April's Patch Tuesday, marking the second-largest security update ever issued by the company. Eight vulnerabilities are classified as ...

      2026-05-22 03:53 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2025-30975.json.

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-30975",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-08-20T13:41:24.151733Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-08-20T13:41:29.519Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "packageName": "add-custom-codes",
              "product": "Add Custom Codes",
              "vendor": "SaifuMak",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "5.0",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "4.80",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Ryan Novotny | Patchstack Bug Bounty Program"
            }
          ],
          "datePublic": "2026-04-01T16:37:48.948Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper Control of Generation of Code ('Code Injection') vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Code Injection.<p>This issue affects Add Custom Codes: from n/a through <= 4.80.</p>"
                }
              ],
              "value": "Improper Control of Generation of Code ('Code Injection') vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Code Injection.This issue affects Add Custom Codes: from n/a through <= 4.80."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-242",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Code Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "Improper Control of Generation of Code ('Code Injection')",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-28T16:12:02.482Z",
            "orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
            "shortName": "Patchstack"
          },
          "references": [
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://patchstack.com/database/Wordpress/Plugin/add-custom-codes/vulnerability/wordpress-add-custom-codes-4-80-arbitrary-code-execution-vulnerability?_s_id=cve"
            }
          ],
          "title": "WordPress Add Custom Codes <= 4.80 - Arbitrary Code Execution vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
        "assignerShortName": "Patchstack",
        "cveId": "CVE-2025-30975",
        "datePublished": "2025-08-20T08:03:47.588Z",
        "dateReserved": "2025-03-26T09:22:34.906Z",
        "dateUpdated": "2026-04-28T16:12:02.482Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }