Cross-Site Scripting Vulnerability in Iulia Cazan's Latest Post Shortcode Plugin
CVE-2025-58609

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 September 2025

What is CVE-2025-58609?

The Cross-Site Scripting vulnerability in Iulia Cazan's Latest Post Shortcode plugin could allow attackers to execute malicious scripts in a user's browser. This typically happens when user-supplied input is improperly sanitized, leading to stored XSS risks. Affected versions include Latest Post Shortcode up to and including 14.0.3, potentially compromising user data and site integrity.

Affected Version(s)

Latest Post Shortcode <= 14.0.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

63n0 (Patchstack Alliance)
.
CVE-2025-58609 : Cross-Site Scripting Vulnerability in Iulia Cazan's Latest Post Shortcode Plugin