Cross-site Scripting Vulnerability in Risk Free Cash On Delivery Plugin by WordPress
CVE-2025-48358

5.9MEDIUM

What is CVE-2025-48358?

The Risk Free Cash On Delivery (COD) – WooCommerce plugin for WordPress is susceptible to an input handling issue that allows attackers to exploit stored cross-site scripting (XSS). By leveraging this vulnerability, an attacker could inject malicious scripts into web pages viewed by users, potentially leading to unauthorized data access, session hijacking, or defacement. The affected versions range from an undefined state through 1.0.4. Website owners are strongly advised to update to the latest version to mitigate these risks.

Affected Version(s)

Risk Free Cash On Delivery (COD) &#8211; WooCommerce <= 1.0.4

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.
CVE-2025-48358 : Cross-site Scripting Vulnerability in Risk Free Cash On Delivery Plugin by WordPress