CVE-2025-58992: WordPress Product Catalog Simple Plugin <= 1.8.2 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode Product Catalog Simple post-type-x allows Stored XSS.This issue affects Product Catalog Simple: from n/a through <= 1.8.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58992?
CVE-2025-58992 is classified as a Stored XSS vulnerability, which can allow attackers to execute scripts in the context of the victim's browser.
How do I fix CVE-2025-58992?
To fix CVE-2025-58992, update the impleCode Product Catalog Simple or WordPress Product Catalog Simple Plugin to version 1.8.3 or later.
What versions are affected by CVE-2025-58992?
CVE-2025-58992 affects impleCode Product Catalog Simple versions up to and including 1.8.2 and the corresponding WordPress Product Catalog Simple Plugin.
What impacts can CVE-2025-58992 have on my website?
Exploitation of CVE-2025-58992 can lead to unauthorized actions by attackers, potentially compromising user accounts and data.
Is user input involved in CVE-2025-58992?
Yes, CVE-2025-58992 specifically involves improper neutralization of user input during web page generation, allowing for cross-site scripting.