VYPR
Medium severity5.9NVD Advisory· Published Sep 22, 2025· Updated Apr 23, 2026

CVE-2025-58669

CVE-2025-58669

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modern Minds Magento 2 WordPress Integration m2wp allows Stored XSS.This issue affects Magento 2 WordPress Integration: from n/a through <= 1.4.2.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Modern Minds Magento 2 WordPress Integration (m2wp) plugin allows authenticated attackers to inject malicious scripts.

Vulnerability

Overview

The Modern Minds Magento 2 WordPress Integration (m2wp) plugin for WordPress is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation. This issue affects all versions from n/a through 1.4.2.1 [1]. The vulnerability is classified as CWE-79 and has a CVSS v3 score of 5.9 (Medium) [1].

Exploitation

Details

Exploitation requires a privileged user role to initiate the attack, and successful exploitation requires user interaction, such as clicking a malicious link, visiting a crafted page, or submitting a form [1]. Once triggered, the attacker can inject arbitrary scripts that are stored on the server and executed when other users (including site visitors) access the affected page.

Impact

A successful attack allows a malicious actor to inject malicious scripts, including redirects, advertisements, and other HTML payloads, into the website. These scripts execute in the browsers of visitors, potentially leading to data theft, session hijacking, or defacement [1].

Mitigation

The vulnerability is actively exploited vulnerability is part of mass-exploit campaigns targeting thousands of websites. Immediate action is required immediate action is to update the affected plugin to a patched version. If updating is not possible, users should contact their hosting provider or web developer for assistance [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.