Cross-site Scripting Vulnerability in Search Cloud One by Thomas Harris
CVE-2025-58883

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 September 2025

What is CVE-2025-58883?

An improper neutralization of input during web page generation vulnerability has been identified in Search Cloud One, developed by Thomas Harris. This flaw allows attackers to execute stored Cross-site Scripting (XSS) attacks, potentially leading to the exposure of sensitive user information or the execution of malicious scripts. The affected versions of Search Cloud One include all releases from n/a through 2.2.5. Organizations using this product are urged to assess their systems for security risks related to this vulnerability.

Affected Version(s)

Search Cloud One <= 2.2.5

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vinit Lakra (Patchstack Alliance)
.
CVE-2025-58883 : Cross-site Scripting Vulnerability in Search Cloud One by Thomas Harris