VYPR
Medium severity5.9NVD Advisory· Published Sep 5, 2025· Updated Apr 23, 2026

CVE-2025-58832

CVE-2025-58832

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly Search by Google search-google allows Stored XSS.This issue affects Search by Google: from n/a through <= 1.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in the Search by Google WordPress plugin (≤1.9) allows attackers with contributor-level access to inject malicious scripts. This vulnerability is already used in mass-exploit campaigns.

The vulnerability is a Stored Cross-Site Scripting (XSS) issue in the 'Search by Google' WordPress plugin, identified as CVE-2025-58832. The plugin fails to properly neutralize user input during web page generation, allowing a contributor-level user to inject arbitrary web scripts or HTML. This improper neutralization is the root cause [1].

Exploitation requires a privileged user with at least 'Contributor' role to perform an action such as clicking a malicious link or visiting a crafted page [1]. The injected payload is stored in the application and subsequently executed in the browsers of visitors. Because the attack originates from an authenticated user, but does not require Administrator privileges, the attack surface remains significant.

The impact includes the ability to inject malicious scripts, such as redirects, advertisements, and other HTML payloads. These scripts execute when any guest visits the compromised site, potentially leading to site defacement, credential theft via phishing, or other malicious activities [1].

As of the publication date, the vulnerability affects all versions up to and including 1.9. Users are strongly advised to update the plugin immediately. Workarounds are not described; if updating is not possible, consulting a hosting provider or web developer is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.