Stored XSS Vulnerability in Laposta WooCommerce by Stijn van der Ree
CVE-2025-49434

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2025

What is CVE-2025-49434?

The Laposta WooCommerce plugin developed by Stijn van der Ree is vulnerable to stored cross-site scripting. This vulnerability occurs due to improper handling of user input during the web page generation process, allowing attackers to inject malicious scripts that can harm users. This issue affects versions from n/a up to 1.9.1. Website administrators should take immediate action to mitigate this risk by updating to the latest version and reviewing input validation practices.

Affected Version(s)

Laposta WooCommerce <= 1.9.1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.