Cross-site Scripting Vulnerability in WPFactory Custom Checkout Fields for WooCommerce
CVE-2025-47504

6.5MEDIUM

What is CVE-2025-47504?

A vulnerability exists in WPFactory Custom Checkout Fields for WooCommerce, allowing attackers to exploit improper sanitization of user input during web page generation. This flaw enables Stored XSS, potentially letting an attacker inject malicious scripts into the site, which can be executed in the browsers of unsuspecting users. It affects versions up to 1.8.3, posing risks to data integrity and user safety.

Affected Version(s)

Custom Checkout Fields for WooCommerce <= 1.8.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

muhammad yudha (Patchstack Alliance)
.