Cross-Site Scripting Vulnerability in WP Wham Crowdfunding for WooCommerce
CVE-2025-32628
7.1HIGH
What is CVE-2025-32628?
The WP Wham Crowdfunding for WooCommerce plugin is susceptible to a Cross-Site Scripting (XSS) vulnerability due to improper handling of user input during the web page generation process. This risk allows attackers to execute arbitrary JavaScript code in the context of the victim's browser, potentially compromising user data and session integrity. Affected versions include all versions up to 3.1.12, highlighting the critical importance for developers and site owners to apply relevant security patches.
Affected Version(s)
Crowdfunding for WooCommerce <= 3.1.12
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) (Patchstack Alliance)