Junglewise Threat Intelligence

CVE-2025-58920: Zootemplate Cerato Reflected XSS

CVE-2025-58920 · Severity: high · CVSS 7.1 · Published 2026-04-10

Executive brief

The Cerato theme for WordPress is vulnerable to a security flaw that allows attackers to execute malicious scripts in a user's browser. This occurs when a user clicks on a specially crafted link, potentially leading to unauthorized actions, data theft, or redirection to malicious websites. As there is currently no official patch, website administrators should exercise caution with untrusted links and consider using web application firewalls.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Zootemplate Cerato theme for WordPress (versions <= 2.2.18) due to improper neutralization of user-supplied input during web page generation. An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a specially crafted page. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized administrative actions. As of the advisory date, no official patch has been released by the vendor.

Affected products

  • Zootemplate Cerato <= 2.2.18

Timeline

  • 2025-09-11: other: Vulnerability reported by researcher
  • 2025-09-16: disclosed: Initial disclosure by Patchstack
  • 2026-04-10: advisory: CVE published to NVD

References