CVE-2025-58230: WordPress ZoloBlocks plugin <= 2.3.12 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes ZoloBlocks allows DOM-Based XSS. This issue affects ZoloBlocks: from n/a through 2.3.9.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes ZoloBlocks zoloblocks allows DOM-Based XSS.This issue affects ZoloBlocks: from n/a through <= 2.3.12.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58230?
The severity of CVE-2025-58230 is considered high due to the potential for DOM-Based Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-58230?
To fix CVE-2025-58230, update the ZoloBlocks plugin to version 2.3.10 or later.
What is the impact of CVE-2025-58230 on my website?
CVE-2025-58230 can allow attackers to execute malicious scripts on your website, potentially compromising user data.
Which software versions are affected by CVE-2025-58230?
CVE-2025-58230 affects ZoloBlocks versions up to and including 2.3.9.
Is CVE-2025-58230 related to other vulnerabilities?
CVE-2025-58230 is specifically related to improper input neutralization in ZoloBlocks, which can lead to cross-site scripting vulnerabilities.