CVE-2025-58030
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly Page-list page-list allows Stored XSS.This issue affects Page-list: from n/a through <= 5.8.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The WordPress Page-list plugin ≤5.8 is vulnerable to Stored XSS, allowing authenticated lower-privilege users to inject malicious scripts that execute when other users visit affected pages.
Vulnerability
Details
The WordPress Page-list plugin versions up to and including 5.8 contain a Stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during page generation. This flaw allows an attacker to inject arbitrary HTML or JavaScript into the plugin’s output, which is then stored on the server and executed in the browsers of visitors [1].
Exploitation
Prerequisites
Exploitation requires the attacker to have a user account with the plugin’s applicable role (often Subscriber or Contributor). No higher privileges are needed. Successful execution depends on another privileged user (e.g., an administrator) performing an action such as previewing or visiting a crafted page, or clicking a malicious link. However, the stored script will also execute automatically for any visitor to the affected page [1].
Impact
An attacker can inject malicious scripts, including redirects, advertisements, or other HTML payloads. This could lead to session hijacking, defacement, or further compromise of the site and its users. The vulnerability has a CVSS v3 base score of 6.5 (Medium) and is known to be targeted in mass-exploit campaigns [1].
Mitigation
The issue has been fixed in version 5.9 of the Page-list plugin. Users are strongly advised to update immediately. If updating is not possible, consulting a hosting provider or web developer for alternative mitigations is recommended. Patchstack users can enable auto-updates for vulnerable plugins [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<= 5.8+ 1 more
- (no CPE)range: <= 5.8
- (no CPE)range: <=5.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.