VYPR
Medium severity5.9NVD Advisory· Published Sep 9, 2025· Updated Apr 28, 2026

CVE-2025-58982

CVE-2025-58982

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixeline Pixeline's Email Protector pixelines-email-protector allows Stored XSS.This issue affects Pixeline's Email Protector: from n/a through <= 1.3.8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in WordPress Pixeline's Email Protector plugin (≤1.3.8) allows attackers to inject malicious scripts via unneutralized input, fixed in 1.4.0.

Vulnerability

Overview

Improper neutralization of input during web page generation in Pixeline's Email Protector plugin for WordPress (versions up to and including 1.3.8) leads to a stored cross-site scripting (XSS) vulnerability [1]. This means that an attacker can inject arbitrary HTML or JavaScript code that gets stored on the server and executed when other users view the affected page.

Exploitation

Exploitation requires a privileged user (such as an administrator) to perform an action like clicking a malicious link or submitting a crafted form [1]. Once triggered, the injected script executes in the context of the victim's browser, potentially affecting site visitors or other administrators.

Impact

Successful exploitation allows an attacker to perform actions such as redirecting users to malicious sites, displaying advertisements, or stealing session cookies, thereby compromising the integrity and security of the WordPress site [1].

Mitigation

The vulnerability has been addressed in version 1.4.0 of the plugin. Users are strongly advised to update immediately. For those unable to update, contacting a hosting provider or web developer for assistance is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.