CVE-2025-58674

WordPress <= 6.8.2 - (Author+) Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requires an attacker to have Author or higher user privileges to execute the attack vector.This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5.1.20, from 5.0 through 5.0.23, from 4.9 through 4.9.27, from 4.8 through 4.8.26, from 4.7 through 4.7.30.


We have discovered 7,827,111 live websites that are affected by CVE-2025-58674.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains7,827,111 live websites (100% of WordPress install base)
Vulnerable Versions
  • from 4.7 through 4.7.30
  • from 4.8 through 4.8.26
  • from 4.9 through 4.9.27
  • from 5 through 5.0.23
  • from 5.1 through 5.1.20
  • from 5.2 through 5.2.22
  • from 5.3 through 5.3.19
  • from 5.4 through 5.4.17
  • from 5.5 through 5.5.16
  • from 5.6 through 5.6.15
  • from 5.7 through 5.7.13
  • from 5.8 through 5.8.11
  • from 5.9 through 5.9.11
  • from 6 through 6.0.10
  • from 6.1 through 6.1.8
  • from 6.2 through 6.2.7
  • from 6.3 through 6.3.6
  • from 6.4 through 6.4.6
  • from 6.5 through 6.5.6
  • from 6.6 through 6.6.3
  • from 6.7 through 6.7.3
  • from 6.8 through 6.8.2
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Sep 23, 2025
  • Updated - Oct 1, 2025

Credits

  • savphill (Patchstack Bug Bounty Program) (finder)
  • John Blackbourn (WordPress core security team lead) (coordinator)

Website Distribution by Country

Number of websites using CVE-2025-58674
United States2,642,004 websites



Germany748,456 websites
Japan464,385 websites
GB343,683 websites
France326,805 websites
Italy262,372 websites
Netherlands239,104 websites
Russia195,515 websites
Poland185,563 websites
Canada184,879 websites

Website Distribution by TLD

Number of websites using CVE-2025-58674
.com3,529,590 websites
.de454,365 websites
.org395,021 websites
.net238,092 websites
.nl207,842 websites
.co.uk198,659 websites
.it179,239 websites
.ru163,340 websites
.com.br142,365 websites
.pl139,613 websites

Websites affected by CVE-2025-58674

Top websites that are affected by CVE-2025-58674. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States**
********.*********.com United States**
***************.org United States***
******.net United States***
**********.com United States***
**********.com United States***
*******.com United States***
*****.net Singapore***
****.*****.com United States***
****.******.com Singapore***
See full domain list

FAQ

CVE-2025-58674 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WordPress
A total of 7,827,111 websites have been identified as vulnerable to CVE-2025-58674, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2025-58674 vulnerability.
WordPress versions up to and including 6.8.2 are vulnerable to CVE-2025-58674.