Cross-site Scripting Vulnerability in WPFactory's Change Add to Cart Button Text Plugin for WooCommerce
CVE-2025-48254

5.4MEDIUM

What is CVE-2025-48254?

The Change Add to Cart Button Text for WooCommerce plugin by WPFactory has a security flaw due to improper handling of input during web page generation. This vulnerability allows for the possibility of Stored Cross-site Scripting (XSS), which can be exploited by attackers to inject malicious scripts into the web application. Users running versions from n/a through 2.2.2 are particularly at risk, as this could lead to unauthorized access or actions within the affected WooCommerce implementations. It is crucial for website administrators to update to the latest version and consider security measures to mitigate such vulnerabilities.

Affected Version(s)

Change Add to Cart Button Text for WooCommerce <= 2.2.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

muhammad yudha (Patchstack Alliance)
.