CVE-2025-57901
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-57901 is a Cross-Site Scripting (XSS) vulnerability (CWE-79) associated with a product from vendor daext, initially published on September 22, 2025. However, this CVE ID has since been rejected or withdrawn by its CVE Numbering Authority, meaning it is no longer considered a valid, distinct vulnerability entry. The estimated CVSS v3.1 base score prior to rejection was 6.5 (Medium), and the EPSS score is approximately 0.034% (Feedly).

Technical details

Prior to its rejection, CVE-2025-57901 was classified under CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), suggesting the root cause involved insufficient sanitization of user-supplied input rendered in web page output. The attack vector was network-based, requiring low privileges and user interaction, with a changed scope indicating potential impact beyond the vulnerable component. Because the CVE has been officially rejected by its Numbering Authority, no authoritative technical write-ups or PoC code are associated with this identifier (Feedly).

Impact

As this CVE has been rejected, no confirmed impact can be attributed to it as a distinct vulnerability. The preliminary classification suggested low confidentiality, integrity, and availability impacts with a changed scope, consistent with a stored or reflected XSS scenario that could affect end users of a daext product. No confirmed exploitation or data exposure has been documented under this CVE identifier (Feedly).

Exploitability

CVE-2025-57901 has been rejected by its CVE Numbering Authority and carries an EPSS score of approximately 0.034%, indicating a very low probability of exploitation. There is no evidence of in-the-wild exploitation, no known PoC code, no threat actor attribution, and it does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).

Mitigation and workarounds

Because CVE-2025-57901 has been officially rejected by its CVE Numbering Authority, no specific patches or workarounds are required under this identifier. Organizations using daext WordPress plugins should ensure they are running the latest available versions and follow general XSS hardening practices (input validation, output encoding, Content Security Policy headers). Monitor the daext vendor advisories and the Wordfence vulnerability database for any re-issued or replacement CVE entries (Wordfence).

Community reactions

The CVE was briefly referenced in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of September 22–28, 2025, and in a Red Packet Security CISA vulnerability summary for the same week, before its rejection status became widely known. No significant vendor statements, researcher commentary, or media coverage has been documented specifically for this CVE identifier (Wordfence, Red Packet Security).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-13784CRITICAL9.8
  • arforms-form-builder
NoYesAug 16, 2026
CVE-2026-17087HIGH7.5
  • wp-travel-engine
NoYesAug 16, 2026
CVE-2026-2497HIGH7.2
  • gallery-plugin
NoYesAug 16, 2026
CVE-2026-17608MEDIUM6.5
  • wp-compress-image-optimizer
NoYesAug 16, 2026
CVE-2026-2357MEDIUM6.4
  • bold-page-builder
NoYesAug 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management