Cross-site Scripting Vulnerability in SEO Auto Linker by Arjan Olsder
CVE-2025-58791

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 September 2025

What is CVE-2025-58791?

A vulnerability in the SEO Auto Linker plugin by Arjan Olsder has been identified, allowing for improper neutralization of input during web page generation. This flaw can lead to stored cross-site scripting (XSS) attacks, enabling an attacker to inject malicious scripts into webpages viewed by unsuspecting users. The vulnerability affects versions up to 1.5.3, highlighting the need for users to implement immediate security measures to protect their applications from potential exploits.

Affected Version(s)

SEO Auto Linker <= 1.5.3

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Que Thanh Tuan - Blue Rock (Patchstack Alliance)
.