CVE-2025-58684: WordPress Logo Showcase plugin <= 4.0.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Logo Showcase allows Stored XSS. This issue affects Logo Showcase: from n/a through 3.0.9.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Logo Showcase logo-showcase allows Stored XSS.This issue affects Logo Showcase: from n/a through <= 4.0.1.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58684?
The severity of CVE-2025-58684 is considered high due to its potential for Stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-58684?
To fix CVE-2025-58684, update the Themepoints Logo Showcase to version 3.0.10 or later.
What types of attacks can CVE-2025-58684 facilitate?
CVE-2025-58684 can facilitate Stored Cross-site Scripting attacks, allowing malicious scripts to run in users' browsers.
What versions of Logo Showcase are affected by CVE-2025-58684?
CVE-2025-58684 affects all versions of the Logo Showcase plugin from n/a up to and including version 3.0.9.
Who is the vendor for CVE-2025-58684?
The vendor for CVE-2025-58684 is Themepoints, responsible for the Logo Showcase software and plugin.