CVE-2025-58970
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-58970 is a Basic XSS (Content Injection) vulnerability in the AmentoTech Doctreat WordPress theme that allows authenticated attackers with subscriber-level privileges to inject malicious script-related HTML tags into web pages. It affects all versions of the Doctreat theme through 1.6.7, with version 1.6.8 containing the fix. The vulnerability was reported on July 3, 2025, by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) and published by Patchstack on August 2, 2025, with CVE assignment on October 22, 2025. It carries a CVSS v3.1 base score of 6.3 (Medium) (Patchstack).

Technical details

The vulnerability is classified as CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page / Basic XSS), which enables code injection via unsanitized user-supplied input rendered in web pages. An authenticated attacker with at minimum subscriber-level access can submit crafted input containing script-related HTML tags that are stored or reflected without proper sanitization, leading to content injection. The attack vector is network-based, requires low privileges, low complexity, and no user interaction per the Patchstack CVSS assessment, suggesting the injected content may be rendered server-side or in contexts not requiring victim interaction (Patchstack).

Impact

Successful exploitation allows an attacker to inject arbitrary HTML content — including script-related tags — into pages and posts of the affected WordPress site, potentially enabling phishing page injection, defacement, or session hijacking of site visitors. The vulnerability has low impact on confidentiality, integrity, and availability individually, but the ability to inject phishing content poses a significant reputational and user-safety risk for affected sites. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their traffic or popularity (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Doctreat theme version 1.6.7 or earlier, using tools like WPScan or by inspecting theme metadata in page source.
  2. Obtain low-privilege access: Register or obtain a subscriber-level account on the target WordPress site, if open registration is enabled.
  3. Identify injection point: Locate input fields within the Doctreat theme that accept and render user-supplied content (e.g., profile fields, booking forms, or other theme-specific inputs).
  4. Inject malicious payload: Submit a crafted payload containing script-related HTML tags (e.g., <script>, <img onerror=...>, or similar) into the vulnerable input field.
  5. Trigger content rendering: The injected content is stored or rendered in a page/post context, potentially executing in the browser of site visitors or administrators, enabling phishing, session theft, or further attacks (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests from low-privilege accounts to theme-specific endpoints containing HTML tag patterns (e.g., <script, onerror=, <img).
  • File System: Unexpected modifications to WordPress posts or pages containing injected HTML/script content when reviewed in the database or via the admin panel.
  • Network: Outbound requests from site visitors' browsers to unknown third-party domains following page visits, potentially indicating active script injection.
  • Application: Presence of unfamiliar HTML content (phishing forms, redirects, or obfuscated scripts) embedded in Doctreat theme-rendered pages (Patchstack).

Mitigation and workarounds

Site owners should update the Doctreat WordPress theme to version 1.6.8 or later, which contains the fix for this vulnerability. As an interim measure, Patchstack offers a virtual patching/mitigation rule that blocks exploitation attempts without requiring an immediate theme update. If neither option is immediately available, disabling open user registration to prevent untrusted users from obtaining subscriber-level accounts can reduce the attack surface (Patchstack).

Community reactions

The vulnerability was discovered and responsibly disclosed by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity, who reported it to Patchstack on July 3, 2025. Patchstack published the advisory on August 2, 2025, and assigned the CVE on October 22, 2025. No significant broader media coverage or notable community discussion has been identified beyond the Patchstack advisory (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13147CRITICAL9.1
  • kirki
NoYesJul 20, 2026
CVE-2026-9833HIGH7.1
  • tag-groups
NoYesJul 20, 2026
CVE-2026-13432MEDIUM5.4
  • image-sizes
NoYesJul 20, 2026
CVE-2026-13156MEDIUM5.4
  • mailersend-official-smtp-integration
NoYesJul 20, 2026
CVE-2026-8825MEDIUM4.9
  • elementor
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management