First published: Thu Jan 09 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes Free WooCommerce Theme 99fy Extension allows Stored XSS.This issue affects Free WooCommerce Theme 99fy Extension: from n/a through 1.2.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
HasThemes Free WooCommerce Theme 99fy Extension | <=1.2.8 | |
HasThemes Free WooCommerce Theme 99fy Extension | <=1.2.8 |
Update the WordPress Free WooCommerce Theme 99fy Extension wordpress plugin to the latest available version (at least 1.2.9).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22801 has been classified as a medium severity vulnerability due to its potential to allow stored cross-site scripting (XSS).
To fix CVE-2025-22801, update the HasThemes Free WooCommerce Theme 99fy Extension to version 1.2.9 or later.
CVE-2025-22801 affects the HasThemes Free WooCommerce Theme 99fy Extension versions prior to 1.2.9.
CVE-2025-22801 is categorized as a Cross-Site Scripting (XSS) vulnerability.
CVE-2025-22801 is a type of stored XSS vulnerability that is relatively common in web applications that improperly handle user input.