VYPR
Medium severity5.9NVD Advisory· Published Sep 22, 2025· Updated Apr 23, 2026

CVE-2025-58266

CVE-2025-58266

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fumiki Takahashi Gianism gianism allows Stored XSS.This issue affects Gianism: from n/a through <= 6.0.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Gianism WordPress plugin through ≤6.0.0 allows attackers to inject malicious scripts executed when visitors load affected pages.

Vulnerability

Overview CVE-2025-58266 is a stored cross-site scripting (XSS) vulnerability in the Gianism WordPress plugin by Fumiki Takahashi, affecting versions from n/a through 6.0.0. The root cause is improper neutralization of user-supplied input during web page generation, allowing stored injection of arbitrary HTML and JavaScript [1].

Attack

Vector Exploitation requires a privileged user (e.g., an administrator) to perform an action such as clicking a crafted link or submitting a form, after which the malicious payload is stored and later executed in the browsers of visitors [1]. The vulnerability is classified as medium severity (CVSS v3 base 5.9) and does not require authentication for the stored payload, only for initial injection by a privileged role.

Impact

A successful attack enables an actor to inject malicious scripts—such as redirects, advertisements, or other HTML payloads—that execute when guests visit the affected website. This can lead to defacement, phishing, or malware distribution, and is noted to be frequently used in mass-exploit campaigns targeting thousands of sites [1].

Mitigation

Users are strongly advised to update the Gianism plugin immediately to a patched version. If updating is not possible, contact your hosting provider or a web developer for assistance. The vulnerability is publicly documented, and no workaround beyond patching has been provided [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.