CVE-2025-58674

WordPress <= 6.8.2 - (Author+) Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requires an attacker to have Author or higher user privileges to execute the attack vector.This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5.1.20, from 5.0 through 5.0.23, from 4.9 through 4.9.27, from 4.8 through 4.8.26, from 4.7 through 4.7.30.


We have discovered 1,040,458 live websites that are affected by CVE-2025-58674.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains1,040,458 live websites (13% of WordPress install base)
Vulnerable Versions
  • from 4.7 through 4.7.30
  • from 4.8 through 4.8.26
  • from 4.9 through 4.9.27
  • from 5 through 5.0.23
  • from 5.1 through 5.1.20
  • from 5.2 through 5.2.22
  • from 5.3 through 5.3.19
  • from 5.4 through 5.4.17
  • from 5.5 through 5.5.16
  • from 5.6 through 5.6.15
  • from 5.7 through 5.7.13
  • from 5.8 through 5.8.11
  • from 5.9 through 5.9.11
  • from 6 through 6.0.10
  • from 6.1 through 6.1.8
  • from 6.2 through 6.2.7
  • from 6.3 through 6.3.6
  • from 6.4 through 6.4.6
  • from 6.5 through 6.5.6
  • from 6.6 through 6.6.3
  • from 6.7 through 6.7.3
  • from 6.8 through 6.8.2
Vulnerable Versions Count323 versions ( 22% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Sep 23, 2025
  • Updated - Apr 28, 2026

Credits

  • savphill (Patchstack Bug Bounty Program) (finder)
  • John Blackbourn (WordPress core security team lead) (coordinator)

Website Distribution by Country

Number of websites using CVE-2025-58674
United States280,107 websites



Japan99,160 websites
Germany86,257 websites
Italy48,997 websites
Russia43,535 websites
GB42,371 websites
Poland38,755 websites
France35,020 websites
Netherlands28,552 websites
Spain24,157 websites

Website Distribution by TLD

Number of websites using CVE-2025-58674
.com426,985 websites
.de49,622 websites
.org45,826 websites
.ru37,684 websites
.net33,504 websites
.it32,945 websites
.pl29,726 websites
.nl24,592 websites
.co.uk23,134 websites
.jp22,681 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-58674

Top websites that are affected by CVE-2025-58674. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.net Canada***
****.******.com Singapore***
*********.space United States***
****************.com United States***
********.info United States***
***************.org United States***
******.com United States***
****.*****.net United States***
**********.com United States***
******.*******.org United States***
See full domain list

FAQ

CVE-2025-58674 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WordPress
A total of 1,040,458 websites have been identified as vulnerable to CVE-2025-58674, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2025-58674 vulnerability.
WordPress versions up to and including 6.8.2 are vulnerable to CVE-2025-58674.