Stored XSS Vulnerability in WPFactory Product Notes for WooCommerce
CVE-2025-48239
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 May 2025
What is CVE-2025-48239?
A stored cross-site scripting (XSS) vulnerability exists in the WPFactory Product Notes Tab & Private Admin Notes for WooCommerce plugin. This flaw allows attackers to inject malicious scripts into the application's web pages, which can then be executed in the browsers of users who view these pages. This vulnerability is particularly concerning as it can lead to unauthorized data exposure, session hijacking, and other malicious activities. The affected versions range from any prior version through 3.1.0, making it imperative for users to update to secure their environments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Product Notes Tab & Private Admin Notes for WooCommerce <= 3.1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved