Reflected XSS Vulnerability in Munzir's MyShouts Shoutbox Plugin
CVE-2025-58916

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 October 2025

What is CVE-2025-58916?

The MyShouts Shoutbox plugin developed by Munzir is susceptible to a reflected Cross-site Scripting (XSS) vulnerability. This flaw allows an attacker to inject arbitrary web scripts, which can be executed in the context of a user's browser when they interact with a crafted URL. The vulnerability primarily affects users running the plugin version 0.9 or earlier, potentially leading to session hijacking, data theft, or further exploitation of the affected system.

Affected Version(s)

Author: Munzir 0 <= 0.9

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien (Patchstack Alliance)
.