Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS.
WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requires an attacker to have Author or higher user privileges to execute the attack vector.
This issue affects WordPress: from n/a through 6.8.2.
Metrics
Affected Vendors & Products
References
History
Thu, 25 Sep 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Automattic
Automattic wordpress Wordpress Wordpress wordpress |
|
Vendors & Products |
Automattic
Automattic wordpress Wordpress Wordpress wordpress |
Tue, 23 Sep 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 23 Sep 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS. WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requires an attacker to have Author or higher user privileges to execute the attack vector. This issue affects WordPress: from n/a through 6.8.2. | |
Title | WordPress core <= 6.8.2 - (Author+) Cross Site Scripting (XSS) Vulnerability | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-09-23T19:17:35.099Z
Reserved: 2025-09-03T09:03:46.831Z
Link: CVE-2025-58674

Updated: 2025-09-23T19:15:12.007Z

Status : Awaiting Analysis
Published: 2025-09-23T19:15:41.603
Modified: 2025-09-24T18:11:24.520
Link: CVE-2025-58674

No data.