CVE-2025-58964: WordPress Enzy theme < 1.6.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Enzy enzy allows Reflected XSS.This issue affects Enzy: from n/a through < 1.6.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58964?
CVE-2025-58964 has been classified as a medium severity vulnerability due to its potential for exploitation via reflected cross-site scripting.
How do I fix CVE-2025-58964?
To fix CVE-2025-58964, update the Enzy software to version 1.6.4 or later where the vulnerability has been addressed.
What software is affected by CVE-2025-58964?
CVE-2025-58964 affects skygroup Enzy versions prior to 1.6.4 and the WordPress Enzy theme up to version 1.6.4.
What is reflected XSS in CVE-2025-58964?
Reflected XSS in CVE-2025-58964 allows attackers to inject malicious scripts that execute in the user's browser when they visit a compromised URL.
How can I detect CVE-2025-58964 on my website?
To detect CVE-2025-58964, perform a security scan on your website to identify vulnerabilities related to cross-site scripting in the affected Enzy software.