CVE-2025-58267

7.1

Aftabul Islam · Stock Message

A Cross-Site Request Forgery vulnerability in the Aftabul Islam Stock Message plugin allows for Stored Cross-Site Scripting attacks.

Executive summary

The Aftabul Islam Stock Message plugin contains a CSRF vulnerability that enables Stored XSS, posing a significant risk of unauthorized script execution within a user browser.

Vulnerability

This vulnerability is a Cross-Site Request Forgery (CWE-352) that allows an unauthenticated attacker to trigger Stored Cross-Site Scripting. By tricking an authenticated administrator into performing an action, an attacker can inject malicious scripts into the application.

Business impact

The successful exploitation of this vulnerability could lead to session hijacking, unauthorized actions performed on behalf of an administrator, or the theft of sensitive user data. Given the CVSS score of 7.1, this is classified as a High severity issue, as the impact on integrity and confidentiality is significant. Such vulnerabilities can lead to full site compromise if administrative sessions are successfully hijacked.

Remediation

Immediate Action: Since a specific patch version is currently unknown, users should immediately disable or uninstall the Stock Message plugin until the vendor releases a security update.

Proactive Monitoring: Security teams should monitor web server access logs for unusual requests targeting the plugin directory and inspect administrative account activity for unauthorized configuration changes.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious cross-site requests and mitigate potential XSS injection attempts.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

Due to the High severity rating and the potential for Stored XSS, this vulnerability represents a serious security risk to the integrity of the affected WordPress environment. Organizations are urged to prioritize the removal or deactivation of the vulnerable Stock Message plugin until an official vendor patch is identified and applied.

Sources

Originally found and disclosed by Nguyen Xuan Chien | Patchstack Bug Bounty Program, per the CVE Program record.