Cross-site Scripting Vulnerability in WPFactory Custom Checkout Fields for WooCommerce
CVE-2025-47504
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 May 2025
What is CVE-2025-47504?
A vulnerability exists in WPFactory Custom Checkout Fields for WooCommerce, allowing attackers to exploit improper sanitization of user input during web page generation. This flaw enables Stored XSS, potentially letting an attacker inject malicious scripts into the site, which can be executed in the browsers of unsuspecting users. It affects versions up to 1.8.3, posing risks to data integrity and user safety.
Affected Version(s)
Custom Checkout Fields for WooCommerce <= 1.8.3