Custom Background Changer Security & Risk Analysis

wordpress.org/plugins/custom-background-changer

Set a unique background color, gradient, image, overlay, or video for any individual post or page — all from a single elegant meta box.

1K active installs v4.0 PHP 7.4+ WP 6.5+ Updated Jul 9, 2026
background-changercustom-backgroundgradient-backgroundpage-backgroundvideo-background
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEDec 31, 2025
Safety Verdict

Is Custom Background Changer Safe to Use in 2026?

Mostly Safe

Score 78/100

Custom Background Changer is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Dec 31, 2025Updated 1mo ago
Risk Assessment

The custom-background-changer plugin v3.0 exhibits a mixed security posture. Static analysis reveals a very small attack surface with no identified entry points lacking authentication, which is a positive sign. The code also demonstrates good practices in utilizing prepared statements for SQL queries and performing nonce checks. However, a significant concern arises from the output escaping, where a notable percentage (21%) of outputs are not properly escaped, potentially leaving the plugin vulnerable to Cross-Site Scripting (XSS) attacks. Taint analysis yielded no critical or high severity flows, which is encouraging.

The vulnerability history is a major red flag. The plugin has one known CVE, which is currently unpatched and categorized as medium severity, specifically related to Cross-Site Scripting. This indicates a recurring or unaddressed security flaw. While the current code analysis doesn't highlight a direct path for this specific XSS, the historical vulnerability and the unescaped outputs suggest a weakness that could be exploited. The late date of the last vulnerability (2025-12-31) might be a placeholder or indicate a future discovery, but the existence of an unpatched medium CVE is a present risk.

In conclusion, while the plugin has some good security foundations, the unpatched medium severity XSS vulnerability and the unescaped outputs present a clear and present danger. The lack of critical findings in static and taint analysis is positive, but the historical context and the identified output escaping issue necessitate caution. The plugin should be updated or remediated to address the known vulnerability.

Key Concerns

  • Unpatched medium severity CVE
  • Significant unescaped output percentage
Vulnerabilities
1 published

Custom Background Changer Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62125medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Custom Background Changer <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 31, 2025Unpatched
Version History

Custom Background Changer Release Timeline

v4.0Current1 CVE
v3.01 CVE
v2.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Custom Background Changer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
11 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

79% escaped14 total outputs
Attack Surface

Custom Background Changer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_enqueue_scriptscustom-background-changer.php:41
actionadd_meta_boxescustom-background-changer.php:63
actionsave_postcustom-background-changer.php:166
filterbody_classcustom-background-changer.php:213
actionwp_headcustom-background-changer.php:224
Maintenance & Trust

Custom Background Changer Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJul 9, 2026
PHP min version7.4
Downloads47K

Community Trust

Rating98/100
Number of ratings7
Active installs1K
Developer Profile

Custom Background Changer Developer Profile

Anshul Gangrade

5 plugins · 3K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Background Changer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-background-changer/assets/css/cbc-metabox.css/wp-content/plugins/custom-background-changer/assets/js/cbc-metabox.js
Script Paths
/wp-content/plugins/custom-background-changer/assets/js/cbc-metabox.js

HTML / DOM Fingerprints

CSS Classes
cbc-infocbc-field-wrapcbc-row-titlecbc-row-contentcbc-bgcolorcbc-bgimagecbc-bg-attachcbc-bgrepeat+1 more
HTML Comments
Copyright 2012 Anshul Labs (email : hello@anshullabs.xyz)This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License, version 2, as published by the Free Software Foundation.This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.You should have received a copy of the GNU General Public License along with this program; if not, write to the Free Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA+3 more
Data Attributes
name="cbc-bgoption"id="cbc-bg-option-one"id="cbc-bg-option-two"name="cbc-bgcolor"class="cbc-bgcolor"name="cbc-bgimage"+11 more
JS Globals
meta_image
FAQ

Frequently Asked Questions about Custom Background Changer