Reflected XSS in PeproDev WooCommerce Receipt Uploader
CVE-2025-24574
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 February 2025
What is CVE-2025-24574?
The PeproDev WooCommerce Receipt Uploader plugin contains a reflected cross-site scripting (XSS) vulnerability due to improper neutralization of user inputs during web page generation. This vulnerability allows attackers to inject malicious scripts that can be executed in the context of users’ browsers. The issue affects all versions of the plugin up to 2.6.9. Prompt updates are essential to prevent potential exploitation that could compromise user data and website integrity.
Affected Version(s)
PeproDev WooCommerce Receipt Uploader <= 2.6.9