CVE-2025-3598
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Apr 18, 2025
Updated: Apr 21, 2025
CWE ID 79
Summary
CVE-2025-3598 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Coupon Affiliates plugin for WooCommerce, used in WordPress sites. The issue is caused by insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. By tricking users into clicking on malicious links, attackers can execute these scripts, potentially stealing sensitive information or taking control of affected websites. This vulnerability impacts all versions up to and including .6.3.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.