
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-58970 is a Basic XSS (Content Injection) vulnerability in the AmentoTech Doctreat WordPress theme that allows authenticated attackers with subscriber-level privileges to inject malicious script-related HTML tags into web pages. It affects all versions of the Doctreat theme through 1.6.7, with version 1.6.8 containing the fix. The vulnerability was reported on July 3, 2025, by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) and published by Patchstack on August 2, 2025, with CVE assignment on October 22, 2025. It carries a CVSS v3.1 base score of 6.3 (Medium) (Patchstack).
The vulnerability is classified as CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page / Basic XSS), which enables code injection via unsanitized user-supplied input rendered in web pages. An authenticated attacker with at minimum subscriber-level access can submit crafted input containing script-related HTML tags that are stored or reflected without proper sanitization, leading to content injection. The attack vector is network-based, requires low privileges, low complexity, and no user interaction per the Patchstack CVSS assessment, suggesting the injected content may be rendered server-side or in contexts not requiring victim interaction (Patchstack).
Successful exploitation allows an attacker to inject arbitrary HTML content — including script-related tags — into pages and posts of the affected WordPress site, potentially enabling phishing page injection, defacement, or session hijacking of site visitors. The vulnerability has low impact on confidentiality, integrity, and availability individually, but the ability to inject phishing content poses a significant reputational and user-safety risk for affected sites. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their traffic or popularity (Patchstack).
<script>, <img onerror=...>, or similar) into the vulnerable input field.<script, onerror=, <img).Site owners should update the Doctreat WordPress theme to version 1.6.8 or later, which contains the fix for this vulnerability. As an interim measure, Patchstack offers a virtual patching/mitigation rule that blocks exploitation attempts without requiring an immediate theme update. If neither option is immediately available, disabling open user registration to prevent untrusted users from obtaining subscriber-level accounts can reduce the attack surface (Patchstack).
The vulnerability was discovered and responsibly disclosed by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity, who reported it to Patchstack on July 3, 2025. Patchstack published the advisory on August 2, 2025, and assigned the CVE on October 22, 2025. No significant broader media coverage or notable community discussion has been identified beyond the Patchstack advisory (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."