PT-2025-39206 · Automattic+1 · Wordpress+1

John Blackbourn

+1

·

Published

2025-09-22

·

Updated

2025-12-21

·

CVE-2025-58674

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WordPress versions through 6.8.2
Description A flaw exists in Automattic WordPress that allows for Stored Cross-site Scripting (XSS). An attacker with Author or higher user privileges can exploit this issue. The vulnerability stems from improper neutralization of input during web page generation.
Recommendations Update WordPress to a version later than 6.8.2.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-13139
BIT-WORDPRESS-2025-58674
BIT-WORDPRESS-MULTISITE-2025-58674
CVE-2025-58674
DLA-4358-1
DSA-6075-1
DSA-6091-1

Affected Products

Debian
Wordpress