CVE-2025-58263: WordPress BuddyPress Notification Widget Plugin <= 1.3.3 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev BuddyPress Notification Widget allows Stored XSS. This issue affects BuddyPress Notification Widget: from n/a through 1.3.3.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev BuddyPress Notification Widget buddypress-notifications-widget allows Stored XSS.This issue affects BuddyPress Notification Widget: from n/a through <= 1.3.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58263?
CVE-2025-58263 has been classified as a high-severity vulnerability due to the potential for stored cross-site scripting (XSS).
How do I fix CVE-2025-58263?
To fix CVE-2025-58263, update the BuddyPress Notification Widget to version 1.3.4 or later, which addresses the vulnerability.
What is the impact of CVE-2025-58263?
CVE-2025-58263 allows attackers to execute arbitrary JavaScript code in the context of a user's session, leading to potential data theft or session hijacking.
Which versions are affected by CVE-2025-58263?
CVE-2025-58263 affects BuddyPress Notification Widget version 1.3.3 and earlier.
Who is affected by CVE-2025-58263?
Users utilizing the BuddyDev BuddyPress Notification Widget version 1.3.3 or earlier on their WordPress sites are at risk due to CVE-2025-58263.