CVE-2025-1363

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Mar 9, 2025
Updated: Mar 12, 2025

Summary

CVE-2025-1363 is a stored Cross-Site Scripting (XSS) vulnerability affecting the URL Shortener, Conversion Tracking, and AB Testing features of the WooCommerce WordPress plugin up to version 9.0.2. Even when the unfiltered_html capability is disabled, high privilege users like admins can inject malicious scripts into the plugin's settings, posing a significant security risk. This issue allows attackers to execute arbitrary code in the context of the affected website, potentially leading to unauthorized access, data theft, and other malicious activities.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share