Reflected XSS Vulnerability in WooCommerce Product Table by CodeAstrology Team
CVE-2025-22307

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 January 2025

What is CVE-2025-22307?

A reflected Cross-site Scripting (XSS) vulnerability exists in the Product Table for WooCommerce, developed by CodeAstrology Team. This flaw allows attackers to inject malicious scripts into web pages generated by the application, potentially compromising users who interact with the affected products. Versions from n/a through 3.5.6 are affected, enabling malicious actors to execute arbitrary scripts in the context of users' browsers, which can lead to data theft and session hijacking.

Affected Version(s)

Product Table for WooCommerce 0 <= 4.0.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.