VYPR
Medium severity6.5NVD Advisory· Published Sep 5, 2025· Updated Apr 23, 2026

CVE-2025-58850

CVE-2025-58850

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in marcshowpass Showpass WordPress Extension showpass allows Stored XSS.This issue affects Showpass WordPress Extension: from n/a through <= 4.0.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored Cross-Site Scripting in Showpass WordPress Extension plugin ≤4.0.3 allows attackers to inject malicious scripts via unsanitized input.

The Showpass WordPress Extension plugin (versions up to and including 4.0.3) contains a Stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user input during web page generation. This allows an attacker to inject arbitrary HTML and JavaScript code that is stored on the server and executed when the page is loaded [1].

Exploiting this vulnerability requires the attacker to have at least contributor-level access to the WordPress site, as they need to submit input that is saved and later displayed to other users. However, no additional user interaction is required for the stored XSS to trigger; the injected script will execute automatically when visitors access the affected page [1].

Successful exploitation could lead to a range of malicious actions, including redirecting visitors to phishing sites, injecting unwanted advertisements, or performing actions on behalf of an authenticated administrator. This can compromise the site's integrity and user trust [1].

The vendor has released version 4.0.4 which fixes the issue. Users are strongly advised to update immediately. For those unable to update, restricting contributor-level access or applying a web application firewall may serve as temporary mitigations [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.