Cross-site Scripting Vulnerability in WPFactory's Change Add to Cart Button Text Plugin for WooCommerce
CVE-2025-48254
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 May 2025
What is CVE-2025-48254?
The Change Add to Cart Button Text for WooCommerce plugin by WPFactory has a security flaw due to improper handling of input during web page generation. This vulnerability allows for the possibility of Stored Cross-site Scripting (XSS), which can be exploited by attackers to inject malicious scripts into the web application. Users running versions from n/a through 2.2.2 are particularly at risk, as this could lead to unauthorized access or actions within the affected WooCommerce implementations. It is crucial for website administrators to update to the latest version and consider security measures to mitigate such vulnerabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Change Add to Cart Button Text for WooCommerce <= 2.2.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved