Cross-site Scripting Vulnerability in Simple Text Slider by W1zzard
CVE-2025-58882

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 September 2025

What is CVE-2025-58882?

The Simple Text Slider plugin for WordPress is susceptible to a stored Cross-site Scripting (XSS) vulnerability, allowing attackers to inject malicious scripts during web page generation. This can lead to unauthorized actions being performed on behalf of users and potential data leakage. It impacts all versions from n/a through 1.0.5, underscoring the need for timely updates and security measures.

Affected Version(s)

Simple Text Slider <= 1.0.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.
CVE-2025-58882 : Cross-site Scripting Vulnerability in Simple Text Slider by W1zzard