CVE-2025-1363: easy-broken-link-checker <= 9.0.2 - Admin+ Stored XSS
The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1363?
CVE-2025-1363 is rated as a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-1363?
To fix CVE-2025-1363, upgrade the WooCommerce WordPress plugin to version 9.0.3 or later, which addresses the sanitation issues.
Who is affected by CVE-2025-1363?
CVE-2025-1363 affects users of the WooCommerce WordPress plugin and the Easy Broken Link Checker plugin versions up to 9.0.2.
What kind of attacks can CVE-2025-1363 facilitate?
CVE-2025-1363 can facilitate Stored Cross-Site Scripting (XSS) attacks, allowing high privilege users to execute malicious scripts.
Is authentication required to exploit CVE-2025-1363?
Yes, exploitation of CVE-2025-1363 requires authentication, specifically by high privilege users such as administrators.