CVE-2025-23495
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-23495 is a Cross-site Scripting (XSS) vulnerability affecting WooCommerce Order Search. The flaw, which allows Reflected XSS, occurs due to improper neutralization of user inputs during web page generation. This issue can be exploited by attackers to inject malicious scripts into web pages viewed by other users. WooCommerce Order Search versions from not available to 1.1.0 are susceptible to this vulnerability. Successful exploitation can lead to unauthorized access, data theft, or other malicious activities. Users are advised to update their WooCommerce Order Search plugin to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.