cbcvebase.
CVE-2025-58674
published 2025-09-23

CVE-2025-58674: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team…

PriorityP425medium5.9CVSS 3.1
AVNACLPRHUIRSCCLILAL
EPSS
0.20%
10.3th percentile
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requires an attacker to have Author or higher user privileges to execute the attack vector.This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5.1.20, from 5.0 through 5.0.23, from 4.9 through 4.9.27, from 4.8 through 4.8.26, from 4.7 through 4.7.30.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianwordpress< wordpress 6.1.9+dfsg1-0+deb12u1 (bookworm)wordpress 6.1.9+dfsg1-0+deb12u1 (bookworm)
wordpresswordpress>= 0 < 5.7.14+dfsg1-0+deb11u15.7.14+dfsg1-0+deb11u1
wordpresswordpress>= 0 < 6.1.9+dfsg1-0+deb12u16.1.9+dfsg1-0+deb12u1
wordpresswordpress>= 0 < 6.8.3+dfsg1-0+deb13u16.8.3+dfsg1-0+deb13u1
wordpresswordpress>= 0 < 6.8.3+dfsg1-16.8.3+dfsg1-1
wordpresswordpress4.7 – 4.7.30
wordpresswordpress4.8 – 4.8.26
wordpresswordpress4.9 – 4.9.27
wordpresswordpress5.0 – 5.0.23
wordpresswordpress5.1 – 5.1.20
wordpresswordpress5.2 – 5.2.22
wordpresswordpress5.3 – 5.3.19
wordpresswordpress5.4 – 5.4.17
wordpresswordpress5.5 – 5.5.16
wordpresswordpress5.6 – 5.6.15
wordpresswordpress5.7 – 5.7.13
wordpresswordpress5.8 – 5.8.11
wordpresswordpress5.9 – 5.9.11
wordpresswordpress6.0 – 6.0.10
wordpresswordpress6.1 – 6.1.8
wordpresswordpress6.2 – 6.2.7
wordpresswordpress6.3 – 6.3.6
wordpresswordpress6.4 – 6.4.6
wordpresswordpress6.5 – 6.5.6
wordpresswordpress6.6 – 6.6.3

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
osv5.9MEDIUM
vendor_debian5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.