CVE-2025-23789: WordPress URL Shortener WooCommerce Plugin <= 9.0.2 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tahminajannat URL Shortener | Conversion Tracking | AB Testing | WooCommerce easy-broken-link-checker allows Reflected XSS.This issue affects URL Shortener | Conversion Tracking | AB Testing | WooCommerce: from n/a through <= 9.0.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23789?
CVE-2025-23789 is classified as a medium severity vulnerability due to its ability to allow reflected cross-site scripting (XSS).
How do I fix CVE-2025-23789?
To fix CVE-2025-23789, update the WordPress URL Shortener WooCommerce Plugin to the latest version that addresses the vulnerability.
Who is affected by CVE-2025-23789?
CVE-2025-23789 affects users of the WordPress URL Shortener WooCommerce Plugin version 9.0.2 and earlier.
What types of attacks can CVE-2025-23789 enable?
CVE-2025-23789 can enable attackers to perform reflected cross-site scripting (XSS) attacks, potentially compromising user data.
Is there a patch available for CVE-2025-23789?
Yes, a patch is available for CVE-2025-23789 in the updated version of the WordPress URL Shortener WooCommerce Plugin.