CVE-2025-58822: WordPress WP Mail Plugin <= 1.3 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mndpsingh287 WP Mail allows DOM-Based XSS. This issue affects WP Mail: from n/a through 1.3.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mndpsingh287 WP Mail wp-mail allows DOM-Based XSS.This issue affects WP Mail: from n/a through <= 1.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58822?
CVE-2025-58822 is rated as a moderate severity due to its potential for exploitation via DOM-Based Cross-Site Scripting.
How do I fix CVE-2025-58822?
To fix CVE-2025-58822, upgrade WP Mail to the latest version beyond 1.3 or apply specific patches as recommended by the vendor.
Which versions of WP Mail are affected by CVE-2025-58822?
CVE-2025-58822 affects all versions of WP Mail up to and including version 1.3.
What type of vulnerability is CVE-2025-58822?
CVE-2025-58822 is a Cross-Site Scripting (XSS) vulnerability arising from improper input neutralization in web page generation.
Who is the vendor for the product affected by CVE-2025-58822?
The vendor for the affected product, WP Mail, is mndpsingh287.