CVE-2025-39582: WordPress WP Data Access plugin <= 5.5.36 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Passionate Programmer Peter WP Data Access allows DOM-Based XSS. This issue affects WP Data Access: from n/a through 5.5.36.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Passionate Programmer Peter WP Data Access wp-data-access allows DOM-Based XSS.This issue affects WP Data Access: from n/a through <= 5.5.36.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39582?
CVE-2025-39582 has been classified as a medium severity vulnerability due to its potential for causing Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-39582?
To resolve CVE-2025-39582, update the WP Data Access plugin to version 5.5.37 or later.
What are the potential impacts of CVE-2025-39582?
The exploitation of CVE-2025-39582 may allow attackers to execute arbitrary scripts in the context of the user's browser.
Which versions of WP Data Access are affected by CVE-2025-39582?
CVE-2025-39582 affects WP Data Access versions from n/a up to 5.5.36.
Where can I find more information about CVE-2025-39582?
Further details on CVE-2025-39582 can typically be found in vulnerability databases and security advisories related to WP Data Access.