CVE-2025-32674
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-32674 is a Cross-Site Scripting (XSS) vulnerability affecting WPFactory's Product Excel Import Export & Bulk Edit for WooCommerce plugin. This issue enables an attacker to inject malicious scripts into a webpage, potentially stealing user data or gaining unauthorized access. The vulnerability exists in versions 4.7 and below of the plugin, and could be exploited through improper neutralization of user input during webpage generation. This can lead to Reflected XSS attacks, putting WooCommerce users at risk. It is recommended that users update to the latest version of the plugin or consider disabling the plugin as a temporary measure until a fix is available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.