CVE-2025-5585: SiteOrigin Widgets Bundle <= 1.68.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-url` DOM Element Attribute
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-url DOM Element Attribute in all versions up to, and including, 1.68.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5585?
CVE-2025-5585 has a moderate severity rating due to the potential for Stored Cross-Site Scripting attacks.
What software is affected by CVE-2025-5585?
CVE-2025-5585 affects all versions of the SiteOrigin Widgets Bundle plugin for WordPress up to and including version 1.68.4.
How do I fix CVE-2025-5585?
To fix CVE-2025-5585, update the SiteOrigin Widgets Bundle plugin to the latest version that has addressed this vulnerability.
What kind of attack can CVE-2025-5585 allow?
CVE-2025-5585 allows authenticated attackers to perform Stored Cross-Site Scripting attacks via the 'data-url' DOM Element Attribute.
Who is impacted by CVE-2025-5585?
Users of the SiteOrigin Widgets Bundle plugin for WordPress prior to version 1.68.4 are impacted by CVE-2025-5585.