CVE-2025-58966: WordPress NEX-Forms LITE plugin < 8.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms LITE nex-forms-lite allows Reflected XSS.This issue affects NEX-Forms LITE: from n/a through < 8.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58966?
CVE-2025-58966 has a medium severity rating due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2025-58966?
To fix CVE-2025-58966, upgrade NEX-Forms LITE to version 8.2 or later.
What types of systems are affected by CVE-2025-58966?
CVE-2025-58966 affects any implementation of Basix NEX-Forms LITE prior to version 8.2.
What is the impact of CVE-2025-58966?
The impact of CVE-2025-58966 includes the potential for attackers to execute malicious scripts in the context of the user's browser.
Who should be concerned about CVE-2025-58966?
Website administrators using affected versions of NEX-Forms LITE should be concerned about CVE-2025-58966 due to its security implications.