CVE-2025-22801: WordPress Free WooCommerce Theme 99fy Extension plugin <= 1.2.8 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes Free WooCommerce Theme 99fy Extension 99fy-core allows Stored XSS.This issue affects Free WooCommerce Theme 99fy Extension: from n/a through <= 1.2.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22801?
CVE-2025-22801 has been classified as a medium severity vulnerability due to its potential to allow stored cross-site scripting (XSS).
How do I fix CVE-2025-22801?
To fix CVE-2025-22801, update the HasThemes Free WooCommerce Theme 99fy Extension to version 1.2.9 or later.
What systems are affected by CVE-2025-22801?
CVE-2025-22801 affects the HasThemes Free WooCommerce Theme 99fy Extension versions prior to 1.2.9.
What is the type of vulnerability identified in CVE-2025-22801?
CVE-2025-22801 is categorized as a Cross-Site Scripting (XSS) vulnerability.
Is CVE-2025-22801 a common vulnerability?
CVE-2025-22801 is a type of stored XSS vulnerability that is relatively common in web applications that improperly handle user input.