Impact
The WP Thumbtack Review Slider plugin, vulnerability CVE-2025‑58216, is a stored XSS flaw caused by improper input neutralization. The flaw allows attackers to inject malicious JavaScript that runs in a visitor’s browser when they view a page containing a compromised review, potentially enabling phishing, credential theft, or other client‑side attacks. This vulnerability is identified as CWE‑79.
Affected Systems
The issue affects the jgwhite33 WP Thumbtack Review Slider plugin for WordPress. All releases through 2.6, and any earlier versions lacking the risk mitigation, are impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.9, indicating moderate severity, while the EPSS score is below 1%, suggesting a low probability of exploitation at present. It is not listed in the CISA KEV catalog. The likely attack vector is remote, via a victim’s browser rendering a page that includes a maliciously stored review. An attacker would need to insert malicious payloads into reviews or other stored content before they are served to users.
OpenCVE Enrichment
EUVD