CVE-2025-58828: WordPress 코드엠샵 소셜톡 plugin <= 1.2.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codemstory 코드엠샵 소셜톡 allows Stored XSS. This issue affects 코드엠샵 소셜톡: from n/a through 1.2.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codemstory 코드엠샵 소셜톡 mshop-naver-talktalk allows Stored XSS.This issue affects 코드엠샵 소셜톡: from n/a through <= 1.2.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58828?
CVE-2025-58828 is classified as a high severity vulnerability due to its potential for allowing stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-58828?
To fix CVE-2025-58828, upgrade to a patched version of 코드엠샵 소셜톡 that is higher than 1.2.1.
What are the consequences of exploiting CVE-2025-58828?
Exploiting CVE-2025-58828 can allow an attacker to execute malicious scripts in the context of a user's session, leading to data theft or account compromise.
Which versions are affected by CVE-2025-58828?
CVE-2025-58828 affects 코드엠샵 소셜톡 versions up to and including 1.2.1.
Is there a workaround for CVE-2025-58828?
Currently, the recommended solution for CVE-2025-58828 is to update to the latest version rather than looking for workarounds.