Cross-site Scripting Vulnerability in ONTRAPORT PilotPress
CVE-2025-58238

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2025

What is CVE-2025-58238?

The ONTRAPORT PilotPress plugin is susceptible to Cross-site Scripting (XSS) due to improper handling of input data during web page generation. This vulnerability can lead to stored XSS attacks, where malicious scripts are embedded and executed in the context of other users' sessions. Affected versions include those prior to 2.0.35, making it crucial for users to implement patches and updates to safeguard their applications and data.

Affected Version(s)

PilotPress <= 2.0.35

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zaim (Patchstack Alliance)
.