WordPress Gift Hunt plugin <= 2.0.2 - Cross Site Scripting (XSS) vulnerability
CVE-2025-67631

Currently unrated

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
24 December 2025

What is CVE-2025-67631?

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ecommerce Platforms Gift Hunt gift-hunt allows Stored XSS.This issue affects Gift Hunt: from n/a through <= 2.0.2.

Affected Version(s)

Gift Hunt <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LIM MINHYEOK | Patchstack Bug Bounty Program
.
CVE-2025-67631 : Cross-site Scripting Vulnerability in Gift Hunt by Ecommerce Platforms