CVE-2025-27347
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 24, 2025
CWE ID 79
Summary
CVE-2025-27347 is a Cross-site Scripting (XSS) vulnerability affecting the Direct Checkout Button for WooCommerce. This issue permits attackers to inject malicious scripts into web pages generated by the plugin, exploiting improper input neutralization. The vulnerability, which can lead to stored XSS attacks, affects Direct Checkout Button for WooCommerce versions from n/a through 1.0. Successful exploitation allows attackers to execute arbitrary code in the context of the affected user, potentially leading to account takeover or data theft.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- WordPress