CVE-2025-58610: WordPress Gallery PhotoBlocks Plugin <= 1.3.1 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Gallery PhotoBlocks allows Stored XSS. This issue affects Gallery PhotoBlocks: from n/a through 1.3.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Gallery PhotoBlocks photoblocks-grid-gallery allows Stored XSS.This issue affects Gallery PhotoBlocks: from n/a through <= 1.3.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58610?
The severity of CVE-2025-58610 is categorized as high due to its potential for allowing stored XSS attacks.
How do I fix CVE-2025-58610?
To fix CVE-2025-58610, update the WP Chill Gallery PhotoBlocks plugin to version 1.3.2 or higher.
What versions of Gallery PhotoBlocks are affected by CVE-2025-58610?
CVE-2025-58610 affects WP Chill Gallery PhotoBlocks versions up to and including 1.3.1.
What type of vulnerability is CVE-2025-58610?
CVE-2025-58610 is a Cross-site Scripting (XSS) vulnerability allowing stored attacks.
Who is the vendor for the affected product in CVE-2025-58610?
The vendor for the affected product in CVE-2025-58610 is WP Chill.