Stored Cross-site Scripting Vulnerability in ProWCPlugins Product Time Countdown for WooCommerce
CVE-2025-47505
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 May 2025
What is CVE-2025-47505?
A stored Cross-site Scripting (XSS) vulnerability exists in the ProWCPlugins Product Time Countdown for WooCommerce, allowing an attacker to inject malicious scripts into web pages. This can lead to unauthorized actions being performed on behalf of users, data theft, and compromised site integrity. The vulnerability affects versions ranging from n/a to 1.6.2, highlighting the need for immediate updates to protect websites utilizing this plugin.
Affected Version(s)
Product Time Countdown for WooCommerce <= 1.6.2