CVE-2025-58971: WordPress Doctreat theme <= 1.6.7 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AmentoTech Doctreat doctreat allows Reflected XSS.This issue affects Doctreat: from n/a through <= 1.6.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58971?
CVE-2025-58971 is classified as a reflected Cross-site Scripting (XSS) vulnerability, which can pose significant security risks to users.
How do I fix CVE-2025-58971?
To fix CVE-2025-58971, upgrade AmentoTech Doctreat to a version higher than 1.6.7 or apply appropriate input sanitization measures.
What versions of Doctreat are affected by CVE-2025-58971?
CVE-2025-58971 affects AmentoTech Doctreat versions up to and including 1.6.7.
Can CVE-2025-58971 be exploited without authentication?
Yes, CVE-2025-58971 can be exploited without authentication, allowing attackers to target any user visiting the affected page.
What are the potential impacts of exploiting CVE-2025-58971?
Exploiting CVE-2025-58971 may allow attackers to execute malicious scripts in the context of a user's session, leading to data theft or session hijacking.