CVE-2025-58262: WordPress Sweet Energy Efficiency plugin <= 1.0.8 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in wpdirectorykit Sweet Energy Efficiency allows Stored XSS. This issue affects Sweet Energy Efficiency: from n/a through 1.0.6.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in WPDirectoryKit Sweet Energy Efficiency sweet-energy-efficiency allows Stored XSS.This issue affects Sweet Energy Efficiency: from n/a through <= 1.0.8.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58262?
CVE-2025-58262 is considered a medium severity Cross-Site Request Forgery vulnerability that allows for Stored XSS.
How do I fix CVE-2025-58262?
To fix CVE-2025-58262, upgrade the Sweet Energy Efficiency Plugin to version 1.0.7 or later.
Which versions of the Sweet Energy Efficiency Plugin are affected by CVE-2025-58262?
CVE-2025-58262 affects all versions of the Sweet Energy Efficiency Plugin up to and including 1.0.6.
What impact does CVE-2025-58262 have on my website?
CVE-2025-58262 can allow an attacker to perform unauthorized actions on behalf of users, potentially leading to data theft or site compromise.
Is there a known exploit for CVE-2025-58262?
While there may not be specific known active exploits, the nature of the vulnerability makes it a potential target for malicious actors.