Cross-Site Request Forgery Vulnerability in GeroNikolov Instant Breaking News
CVE-2025-58217

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 August 2025

What is CVE-2025-58217?

A Cross-Site Request Forgery (CSRF) vulnerability in the GeroNikolov Instant Breaking News plugin for WordPress can lead to stored cross-site scripting (XSS) attacks. This weakness allows attackers to generate unauthorized requests on behalf of the user, potentially compromising the safety and integrity of the affected sites. The vulnerability impacts versions from n/a through 1.0 of the Instant Breaking News plugin, highlighting the importance of securing your WordPress installations against such threats.

Affected Version(s)

Instant Breaking News <= 1.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien (Patchstack Alliance)
.
CVE-2025-58217 : Cross-Site Request Forgery Vulnerability in GeroNikolov Instant Breaking News