Stored Cross-Site Scripting Vulnerability in WPFactory Maximum Products per User for WooCommerce
CVE-2025-62096
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 December 2025
What is CVE-2025-62096?
An improper neutralization of input during web page generation allows attackers to exploit a stored cross-site scripting vulnerability in the WPFactory Maximum Products per User for WooCommerce plugin. This vulnerability enables unauthorized users to inject malicious scripts into web pages viewed by others, potentially compromising user data and site integrity. The issue affects versions from n/a up to 4.4.2.
Affected Version(s)
Maximum Products per User for WooCommerce 0 <= 4.4.3