CVE-2025-58805
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetize Pages Light widgetize-pages-light allows Stored XSS.This issue affects Widgetize Pages Light: from n/a through <= 3.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in Widgetize Pages Light plugin <=3.0 allows attackers to inject malicious scripts via improper input neutralization.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the Widgetize Pages Light plugin for WordPress, affecting versions through 3.0. The issue stems from insufficient sanitization of user-supplied input, enabling stored cross-site scripting (XSS) attacks [1].
Exploitation requires a privileged user role, such as an editor or administrator, to perform an action like submitting a form or clicking a crafted link. The attacker must first inject the malicious script, which is then stored and executed when other users (including visitors) access the affected page [1].
Successful exploitation allows an attacker to inject arbitrary HTML and JavaScript payloads, including redirects, advertisements, or other malicious scripts. These scripts execute in the browser of any visitor viewing the compromised page, potentially leading to session hijacking, defacement, or further attacks [1].
The vendor has not released a patched version; the plugin remains vulnerable. As an immediate measure, users should disable or remove the plugin. If possible, ask a hosting provider or web developer for assistance [1]. The vulnerability has a CVSS v3 base score of 5.9 (Medium), and while not yet listed on CISA's Known Exploited Vulnerabilities catalog, similar XSS issues are frequently used in mass exploitation campaigns [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<=3.0+ 1 more
- (no CPE)range: <=3.0
- (no CPE)range: <=3.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.