Cross-site Scripting in Tamara Checkout by Tamara
CVE-2025-23997
6.5MEDIUM
What is CVE-2025-23997?
The Tamara Checkout plugin is susceptible to a Cross-site Scripting (XSS) vulnerability, enabling malicious actors to inject harmful scripts into webpages. This issue, present in Tamara Checkout versions from n/a through 1.9.8, allows attackers to execute scripts in the context of user sessions, potentially leading to data theft or other malicious activities. It is crucial for users to apply available patches and updates to mitigate this risk effectively.
Affected Version(s)
Tamara Checkout 0 <= 1.9.9.1