VYPR
Medium severity6.5NVD Advisory· Published Sep 5, 2025· Updated Apr 23, 2026

CVE-2025-58786

CVE-2025-58786

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VW THEMES Ibtana – Ecommerce Product Addons ibtana-ecommerce-product-addons allows DOM-Based XSS.This issue affects Ibtana – Ecommerce Product Addons: from n/a through <= 0.4.7.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

DOM-Based XSS in Ibtana – Ecommerce Product Addons plugin (≤0.4.7.4.7.6) allows unauthenticated script injection via improper input neutralization.

The Ibtana – Ecommerce Product Addons plugin for WordPress (versions up to and including 0.4.7.6) contains a DOM-Based Cross-Site Scripting (XSS) vulnerability. The root cause is improper neutralization of user-supplied input during web page generation, which allows an attacker to inject arbitrary JavaScript into the DOM of a victim's browser [1].

Exploitation requires user interaction—a privileged user must click a malicious link, visit a crafted page, or submit a specially crafted form. The attack does not require authentication, meaning any unauthenticated visitor can be targeted if they perform the required action is performed [1].

Successful exploitation enables an attacker to execute arbitrary scripts in the context of the victim's browser. This can be used to redirect users to malicious sites, display unauthorized advertisements, or inject other HTML payloads, potentially leading to further compromise of the affected WordPress site [1].

As of the advisory, the vulnerability is unpatched in the affected versions. Users are strongly advised to update the plugin to the latest available version. If updating is not immediately possible, contacting the hosting provider or a web developer for mitigation assistance is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.