Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefano Lissa Include Me allows Stored XSS. This issue affects Include Me: from n/a through 1.3.2.
Metrics
Affected Vendors & Products
Fixes
Solution
Update the WordPress Include Me plugin to the latest available version (at least 1.3.3).
Workaround
No workaround given by the vendor.
References
History
Tue, 09 Sep 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wordpress
Wordpress wordpress |
|
Vendors & Products |
Wordpress
Wordpress wordpress |
Tue, 09 Sep 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefano Lissa Include Me allows Stored XSS. This issue affects Include Me: from n/a through 1.3.2. | |
Title | WordPress Include Me Plugin <= 1.3.2 - Cross Site Scripting (XSS) Vulnerability | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-09-09T16:33:14.876Z
Reserved: 2025-09-06T04:45:22.562Z
Link: CVE-2025-58983

No data.

Status : Received
Published: 2025-09-09T17:16:12.693
Modified: 2025-09-09T17:16:12.693
Link: CVE-2025-58983

No data.

Updated: 2025-09-09T21:31:30Z