PT-2025-39206 · Automattic+1 · Wordpress+1
John Blackbourn
+1
·
Published
2025-09-22
·
Updated
2025-12-21
·
CVE-2025-58674
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
WordPress versions through 6.8.2
Description
A flaw exists in Automattic WordPress that allows for Stored Cross-site Scripting (XSS). An attacker with Author or higher user privileges can exploit this issue. The vulnerability stems from improper neutralization of input during web page generation.
Recommendations
Update WordPress to a version later than 6.8.2.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Wordpress