CVE-2025-59573: WordPress Cozy Blocks Plugin <= 2.1.29 - Content Injection Vulnerability
Published Sep 22, 2025
·Updated
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CozyThemes Cozy Blocks cozy-addons allows Code Injection.This issue affects Cozy Blocks: from n/a through <= 2.1.29.
Affected Software
1 affected component
CozyThemes Cozy Blocks<=2.1.29
Remediation
Information
Update the WordPress Cozy Blocks plugin to the latest available version (at least 2.1.30).
Event History
Sep 22, 2025
CVE Published
via MITRE·06:25 PM
Data Sourced
via MITRE·06:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-59573?
CVE-2025-59573 has a medium severity level due to its ability to allow code injection through XSS functionality.
2
How do I fix CVE-2025-59573?
To fix CVE-2025-59573, update Cozy Blocks to version 2.1.30 or later.
3
What versions are affected by CVE-2025-59573?
CVE-2025-59573 affects Cozy Blocks versions from n/a through 2.1.29.
4
What type of vulnerability is CVE-2025-59573?
CVE-2025-59573 is classified as a Basic XSS vulnerability caused by improper neutralization of script-related HTML tags.
5
What impact does CVE-2025-59573 have on web applications?
CVE-2025-59573 can lead to code injection, allowing attackers to execute malicious scripts in the context of the user’s browser.