Cross-site Scripting Vulnerability in Easy Download Media Counter by Remi Corson
CVE-2025-58867

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 September 2025

What is CVE-2025-58867?

A vulnerability exists in the Easy Download Media Counter plugin by Remi Corson that allows an attacker to exploit improper input neutralization during web page generation, resulting in stored Cross-site Scripting (XSS) attacks. This flaw impacts versions of the plugin from n/a through 1.2, potentially allowing malicious scripts to be injected and executed within a user's browser session, compromising the security of the website and its visitors. It is crucial for users of this plugin to implement appropriate security measures to mitigate the risk associated with this vulnerability.

Affected Version(s)

Easy Download Media Counter <= 1.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.
CVE-2025-58867 : Cross-site Scripting Vulnerability in Easy Download Media Counter by Remi Corson