Stored Cross-Site Scripting Vulnerability in WooCommerce Checkout Files Upload Plugin
CVE-2025-4212

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 November 2025

What is CVE-2025-4212?

The Checkout Files Upload for WooCommerce plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability. This flaw is due to inadequate input sanitization and output escaping in the handling of file uploads, which allows potential attackers to inject arbitrary web scripts within image files. These injected scripts will execute whenever a user interacts with the compromised page, making it imperative for users to upgrade to the latest version to mitigate this risk.

Affected Version(s)

Checkout Files Upload for WooCommerce * <= 2.2.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

RIN MIYACHI
.