CVE-2025-26762
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Summary
CVE-2025-26762 is a Cross-site Scripting (XSS) vulnerability affecting WooCommerce versions from n/a through 9.7.0. This issue arises due to improper neutralization of user input during web page generation, allowing an attacker to inject and execute malicious scripts on a victim's browser. The implications of this vulnerability include potential data theft, account takeover, and other malicious activities. Successful exploitation occurs when an attacker can inject malicious code into web pages viewed by other users, making it essential for affected WooCommerce installations to be updated to the latest version as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- WooCommerce
Affected Vendors
- Woocommerce