CVE-2025-58674
published 2025-09-23CVE-2025-58674: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team…
PriorityP425medium5.9CVSS 3.1
AVNACLPRHUIRSCCLILAL
EPSS
0.20%
10.3th percentile
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requires an attacker to have Author or higher user privileges to execute the attack vector.This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5.1.20, from 5.0 through 5.0.23, from 4.9 through 4.9.27, from 4.8 through 4.8.26, from 4.7 through 4.7.30.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 6.1.9+dfsg1-0+deb12u1 (bookworm) | wordpress 6.1.9+dfsg1-0+deb12u1 (bookworm) |
| wordpress | wordpress | >= 0 < 5.7.14+dfsg1-0+deb11u1 | 5.7.14+dfsg1-0+deb11u1 |
| wordpress | wordpress | >= 0 < 6.1.9+dfsg1-0+deb12u1 | 6.1.9+dfsg1-0+deb12u1 |
| wordpress | wordpress | >= 0 < 6.8.3+dfsg1-0+deb13u1 | 6.8.3+dfsg1-0+deb13u1 |
| wordpress | wordpress | >= 0 < 6.8.3+dfsg1-1 | 6.8.3+dfsg1-1 |
| wordpress | wordpress | 4.7 – 4.7.30 | — |
| wordpress | wordpress | 4.8 – 4.8.26 | — |
| wordpress | wordpress | 4.9 – 4.9.27 | — |
| wordpress | wordpress | 5.0 – 5.0.23 | — |
| wordpress | wordpress | 5.1 – 5.1.20 | — |
| wordpress | wordpress | 5.2 – 5.2.22 | — |
| wordpress | wordpress | 5.3 – 5.3.19 | — |
| wordpress | wordpress | 5.4 – 5.4.17 | — |
| wordpress | wordpress | 5.5 – 5.5.16 | — |
| wordpress | wordpress | 5.6 – 5.6.15 | — |
| wordpress | wordpress | 5.7 – 5.7.13 | — |
| wordpress | wordpress | 5.8 – 5.8.11 | — |
| wordpress | wordpress | 5.9 – 5.9.11 | — |
| wordpress | wordpress | 6.0 – 6.0.10 | — |
| wordpress | wordpress | 6.1 – 6.1.8 | — |
| wordpress | wordpress | 6.2 – 6.2.7 | — |
| wordpress | wordpress | 6.3 – 6.3.6 | — |
| wordpress | wordpress | 6.4 – 6.4.6 | — |
| wordpress | wordpress | 6.5 – 6.5.6 | — |
| wordpress | wordpress | 6.6 – 6.6.3 | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
osv5.9MEDIUM
vendor_debian5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2025-58674: wordpress - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...
vendor_debian·2025·CVSS 5.9
CVE-2025-58674 [MEDIUM] CVE-2025-58674: wordpress - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requires an attacker to have Author or higher user privileges to execute the attack vector.This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5
OSV
CVE-2025-58674: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS
osv·2025-09-23·CVSS 5.9
CVE-2025-58674 [MEDIUM] CVE-2025-58674: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requires an attacker to have Author or higher user privileges to execute the attack vector.This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5
GHSA
GHSA-73p8-vhmr-7r6r: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS
ghsa_unreviewed·2025-09-23
CVE-2025-58674 [MEDIUM] CWE-79 GHSA-73p8-vhmr-7r6r: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS.
WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requires an attacker to have Author or higher user privileges to execute the attack vector.
This issue affects WordPress: from n/a through 6.8.2.
No detection rules found.
No public exploits indexed.
2025-09-23
Published