Stored Cross-Site Scripting Vulnerability in Dynamic AJAX Product Filters for WooCommerce Plugin
CVE-2025-8073
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 August 2025
What is CVE-2025-8073?
The Dynamic AJAX Product Filters for WooCommerce plugin is vulnerable to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping for the 'name' parameter. This vulnerability allows authenticated attackers with Contributor-level access and above to inject malicious web scripts into pages. These scripts will execute whenever a user visits the compromised page, posing a serious risk to site security and user data integrity.
Affected Version(s)
Dynamic AJAX Product Filters for WooCommerce * <= 1.3.7