CVE-2025-58970: WordPress Doctreat theme <= 1.6.7 - Content Injection vulnerability
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AmentoTech Doctreat doctreat allows Code Injection.This issue affects Doctreat: from n/a through <= 1.6.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58970?
CVE-2025-58970 is classified as a medium severity vulnerability due to its potential for code injection and XSS attacks.
How do I fix CVE-2025-58970?
To fix CVE-2025-58970, update AmentoTech Doctreat to version 1.6.8 or later to mitigate the vulnerability.
Who is affected by CVE-2025-58970?
The CVE-2025-58970 vulnerability affects users of AmentoTech Doctreat versions 1.6.7 and earlier, as well as the WordPress Doctreat theme.
What type of vulnerability is CVE-2025-58970?
CVE-2025-58970 is related to improper neutralization of script-related HTML tags, specifically a basic XSS vulnerability.
Can CVE-2025-58970 lead to data theft?
Yes, CVE-2025-58970 can potentially allow attackers to inject malicious code, which may lead to data theft and unauthorized access.