VYPR
Medium severity6.5NVD Advisory· Published Sep 22, 2025· Updated Apr 23, 2026

CVE-2025-58238

CVE-2025-58238

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ONTRAPORT PilotPress pilotpress allows Stored XSS.This issue affects PilotPress: from n/a through <= 2.0.36.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in ONTRAPORT PilotPress <=2.0.36 allows authenticated attackers to inject malicious scripts executed when visitors view affected pages.

Root

Cause CVE-2025-58238 is a stored cross-site scripting (XSS) vulnerability in the ONTRAPORT PilotPress WordPress plugin, affecting versions through 2.0.36. The plugin fails to properly neutralize user-supplied input during web page generation, allowing attacker-controlled scripts to be permanently stored on the server [1].

## Exploitation & Prerequisites An authenticated attacker with a privileged role (such as Administrator or Editor) must perform an action—like clicking a crafted link or submitting a malicious form—to inject the payload. Once stored, the malicious script executes automatically for any visitor viewing the compromised page or post, requiring no further interaction from the victim [1].

Impact

Successful exploitation enables the attacker to deploy arbitrary JavaScript, redirect users to malicious sites, inject unwanted advertisements, or steal session cookies. This can lead to full site compromise or phishing attacks against site visitors [1].

Mitigation

The vulnerability is patched in versions after 2.0.36. The vendor and Patchstack strongly recommend updating immediately. If an update is not possible, site owners should consult their hosting provider or web developer for interim protection measures [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.