Custom Background Changer
Custom Background Changer has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Custom Background Changer has a vendor fix available, so running the current release closes it.
All of these findings were reported by Muhammad Yudha - DJ. Custom Background Changer is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-62125Custom Background Changer <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Custom Background Changer
Author
Anshul Gangrade
Custom Background Changer lets you control the background of every post and page individually. Go far beyond plain colors with beautiful CSS gradients, full-screen background images, translucent color overlays, and looping MP4 video backgrounds — all from a premium tabbed settings panel right inside the post editor. Features in v4.0 Solid Color – Pick any background color via the color picker. CSS Gradient – Pick two colors and an angle to generate a smooth linear gradient. Background Image – Upload an image with full control over attachment, repeat, position, and size (including cover/contain). Color Overlay – Add a translucent color layer on top of your image or video to improve text readability. MP4 Video Background – Set a looping, auto-playing, muted video as your page background. Performance – CSS and JS assets load only on post/page edit screens in the admin. Zero impact on all other pages. Secure – All input is sanitized. All output is properly escaped. Nonce-protected saves.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C