CVE-2025-3814

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 79

Summary

CVE-2025-3814 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Tax Switch plugin for WooCommerce on WordPress. The flaw, present in versions up to 1.4.2, allows authenticated attackers with Contributor-level access or higher to inject malicious scripts into pages. This can result in the execution of arbitrary code whenever a user accesses an injected page. The root cause is insufficient input sanitization and output escaping in the 'class-name' parameter.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share