Security readout for executives and security teams
Plain-English summary
A reflected cross-site scripting flaw affects the Doctreat WordPress theme (versions up to 1.6.7) from AmentoTech. An attacker who tricks a logged-in user into clicking a crafted link can run script in that user's browser, potentially stealing sessions or defacing pages on healthcare-directory sites built with this theme.
Executive priority
Treat as a high-priority hygiene item for any site using the Doctreat theme: schedule patching this sprint, confirm no admin sessions were abused, and document compensating controls. Lower priority for organizations not running this theme.
Technical view
CWE-79 reflected XSS in AmentoTech's Doctreat theme through 1.6.7. CVSS 3.1 score 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L) reflects network reach, no privileges, required user interaction, and a scope change indicating script can affect resources beyond the vulnerable component. No patched version, exact sink, or affected parameter is named in the cited Patchstack and CVE Program records.
Likely exposure
Limited to WordPress sites running the Doctreat theme (a doctor/medical-directory template). Exposure scales with public-facing instances, especially those with logged-in administrators or members. Sites without this theme are unaffected; the advisory does not name plugin or core dependencies that would broaden the footprint.
Exploitation context
Not listed in CISA KEV and no public exploitation has been cited in the source bundle. The CVSS vector requires user interaction, so realistic abuse involves social-engineered links targeting admins or authenticated users to hijack sessions or pivot within the WordPress dashboard.
Researcher notes
Sources do not specify the vulnerable parameter, sink, or a fixed version; the affected entry lists "0" with default status "unaffected", which is ambiguous. Patchstack typically gates technical detail behind a paid tier, so plan to validate by reviewing theme changelogs and diffing 1.6.7 against any later release once published.
Mitigation direction
- Inventory WordPress sites for the Doctreat theme and confirm installed version.
- Check AmentoTech and Patchstack for an updated Doctreat release and apply it once available.
- Restrict admin access via IP allowlists, MFA, and least-privilege roles until patched.
- Place the site behind a WAF with reflected-XSS rules to filter suspicious query parameters.
- Warn administrators and editors against clicking unsolicited links to the site.
- If no fix exists, evaluate temporarily disabling or replacing the theme on critical sites.
Validation and detection
- Confirm theme presence and version in wp-content/themes and the WordPress admin Themes screen.
- Cross-reference Patchstack's advisory page for any later fixed-version disclosure.
- Review web server and WAF logs for unusual query strings hitting Doctreat endpoints.
- Audit administrator and editor accounts for unexpected sessions or content changes.
- Verify Content Security Policy and HttpOnly/Secure cookie flags are enforced site-wide.
- Re-test after vendor patch using a non-production clone before production rollout.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2025-58971 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.1 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L2.83.7Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.1HighVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Source materials
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
