Cross-site Scripting Vulnerability in WPFactory's Change Add to Cart Button Text Plugin for WooCommerce
CVE-2025-48254
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 May 2025
What is CVE-2025-48254?
The Change Add to Cart Button Text for WooCommerce plugin by WPFactory has a security flaw due to improper handling of input during web page generation. This vulnerability allows for the possibility of Stored Cross-site Scripting (XSS), which can be exploited by attackers to inject malicious scripts into the web application. Users running versions from n/a through 2.2.2 are particularly at risk, as this could lead to unauthorized access or actions within the affected WooCommerce implementations. It is crucial for website administrators to update to the latest version and consider security measures to mitigate such vulnerabilities.
Affected Version(s)
Change Add to Cart Button Text for WooCommerce <= 2.2.2