CVE-2025-1363
CVSS 3.1 Score 3.5 of 10 (low)
Details
Published Mar 9, 2025
Updated: Mar 12, 2025
Summary
CVE-2025-1363 is a stored Cross-Site Scripting (XSS) vulnerability affecting the URL Shortener, Conversion Tracking, and AB Testing features of the WooCommerce WordPress plugin up to version 9.0.2. Even when the unfiltered_html capability is disabled, high privilege users like admins can inject malicious scripts into the plugin's settings, posing a significant security risk. This issue allows attackers to execute arbitrary code in the context of the affected website, potentially leading to unauthorized access, data theft, and other malicious activities.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.