Cross-site Scripting Vulnerability in Form Generator for WordPress by tmontg1
CVE-2025-58665

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2025

What is CVE-2025-58665?

The Form Generator plugin for WordPress by tmontg1 is vulnerable to a Cross-site Scripting (XSS) issue, allowing attackers to inject malicious scripts. This vulnerability specifically allows for Stored XSS, enabling remote attackers to execute arbitrary JavaScript code in the context of affected users. Consequently, this could lead to compromised user sessions, unauthorized actions on behalf of users, or the exposure of sensitive information.

Affected Version(s)

Form Generator for WordPress <= 1.5.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xVenus (Patchstack Alliance)
.