Cross-Site Scripting Vulnerability in WooCommerce Additional Fees Plugin by WPSuperiors
CVE-2025-57903
5.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 September 2025
What is CVE-2025-57903?
A vulnerability has been identified in the WooCommerce Additional Fees On Checkout (Free) plugin by WPSuperiors that allows for Cross-Site Scripting (XSS). When exploited, this flaw permits an attacker to inject malicious scripts into web pages viewed by users, potentially leading to unauthorized actions or information theft. This issue is present in versions of the plugin from n/a through 1.5.0.
Affected Version(s)
WooCommerce Additional Fees On Checkout (Free) <= 1.5.0