CVE-2025-58257
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Picture-Planet GmbH Verowa Connect verowa-connect allows Stored XSS.This issue affects Verowa Connect: from n/a through <= 3.2.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in Verowa Connect plugin up to v3.2.3 allows authenticated attackers to inject arbitrary scripts viewed by site visitors.
CVE-2025-58257 describes a Stored Cross-Site Scripting (XSS) vulnerability in the Verowa Connect WordPress plugin by Picture-Planet GmbH. The issue stems from improper neutralization of user-supplied input during web page generation, as detailed in the official description. This weakness affects all plugin versions from n/a through 3.2.3 [1].
The vulnerability can be exploited by an authenticated user with sufficient privileges (e.g., an editor or administrator) who injects malicious script payloads into fields that are later rendered on the site. Successful exploitation requires the attacker to have a privileged role, and the stored script will execute when other users or visitors access the affected page(s) [1]. No additional user interaction beyond the initial injection is required for the payload to persist.
Impact includes the ability to inject arbitrary HTML and JavaScript, which could be used to redirect visitors, display advertisements, steal session cookies, or perform other client-side attacks. The CVSS v3.1 base score is 6.5 (Medium), reflecting the need for authenticated access but the significant consequence to the site's visitors [1].
The vendor has addressed the flaw in version 3.3.0 of the plugin. Users are strongly advised to update to 3.3.0 or later, which resolves the vulnerability. Patchstack users may enable auto-updates for affected plugins. As with many WordPress plugin vulnerabilities, timely updating is the primary mitigation against potential exploitation [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<=3.2.3+ 1 more
- (no CPE)range: <=3.2.3
- (no CPE)range: <=3.2.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.