CVE-2025-58220: WordPress Card Elements for WPBakery plugin <= 1.0.9 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Techeshta Card Elements for WPBakery allows DOM-Based XSS. This issue affects Card Elements for WPBakery: from n/a through 1.0.8.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Techeshta Card Elements for WPBakery card-elements-for-wpbakery allows DOM-Based XSS.This issue affects Card Elements for WPBakery: from n/a through <= 1.0.9.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58220?
CVE-2025-58220 has a high severity level due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2025-58220?
To fix CVE-2025-58220, update the Techeshta Card Elements for WPBakery to version 1.0.9 or later.
What type of vulnerability is CVE-2025-58220?
CVE-2025-58220 is classified as a Cross-Site Scripting (XSS) vulnerability.
Which versions of the software are affected by CVE-2025-58220?
CVE-2025-58220 affects Techeshta Card Elements for WPBakery versions up to and including 1.0.8.
What is the impact of exploiting CVE-2025-58220?
Exploiting CVE-2025-58220 can allow attackers to execute arbitrary JavaScript in the context of a user's session.