CVE-2025-59556: WordPress GoStore theme < 1.6.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup GoStore gostore allows Reflected XSS.This issue affects GoStore: from n/a through < 1.6.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59556?
CVE-2025-59556 is classified as a high severity vulnerability due to its potential to allow reflected Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-59556?
To fix CVE-2025-59556, upgrade GoStore to version 1.6.4 or later, where the vulnerability is patched.
Which versions of GoStore are affected by CVE-2025-59556?
CVE-2025-59556 affects all versions of GoStore from n/a up to but not including version 1.6.4.
What is reflected XSS as related to CVE-2025-59556?
Reflected XSS in the context of CVE-2025-59556 occurs when user input is not properly sanitized, allowing malicious scripts to be executed in users' browsers.
Can CVE-2025-59556 affect WordPress themes?
Yes, CVE-2025-59556 also affects the WordPress GoStore theme versions prior to 1.6.4.