Bug 2397671 (CVE-2025-58674) - CVE-2025-58674 wordpress: WordPress Cross Site Scripting (XSS)
Summary: CVE-2025-58674 wordpress: WordPress Cross Site Scripting (XSS)
Keywords:
Status: NEW
Alias: CVE-2025-58674
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2397729 2397731 2397733 2397735
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-09-23 19:01 UTC by OSIDB Bzimport
Modified: 2025-09-23 23:00 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-09-23 19:01:36 UTC
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS.

WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requires an attacker to have Author or higher user privileges to execute the attack vector. 
This issue affects WordPress: from n/a through 6.8.2.


Note You need to log in before you can comment on or make changes to this bug.