CVE-2025-58787: WordPress Themify Popup Plugin <= 1.4.2 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Popup allows Stored XSS. This issue affects Themify Popup: from n/a through 1.4.4.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Popup themify-popup allows Stored XSS.This issue affects Themify Popup: from n/a through <= 1.4.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58787?
CVE-2025-58787 has a severity that indicates a critical security risk due to Stored Cross-site Scripting (XSS) in Themify Popup.
How do I fix CVE-2025-58787?
To fix CVE-2025-58787, upgrade Themify Popup to version 1.4.5 or higher.
What versions are affected by CVE-2025-58787?
CVE-2025-58787 affects Themify Popup versions up to and including 1.4.4.
Is CVE-2025-58787 exploitable on all installations?
CVE-2025-58787 is exploitable on all installations of the affected versions of Themify Popup.
What is Stored XSS related to CVE-2025-58787?
Stored XSS in CVE-2025-58787 allows malicious scripts to be permanently stored on the server and executed in users' browsers.