Cross-site Scripting Vulnerability in Lehel Mátyus Legal Terms Popup for WooCommerce
CVE-2025-47592
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 May 2025
What is CVE-2025-47592?
A vulnerability has been identified in the Lehel Mátyus Legal Terms and Conditions Popup for User Login and WooCommerce Checkout – TPUL plugin that allows for cross-site scripting (XSS). This issue arises from improper neutralization of user input during web page generation, enabling attackers to inject malicious scripts. When exploited, this stored XSS vulnerability can compromise user data and lead to unauthorized actions within the affected web application. Users of versions prior to 2.0.3 should take immediate measures to secure their sites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Legal Terms and Conditions Popup for User Login and WooCommerce Checkout – TPUL <= 2.0.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved