CVE-2025-26541: WordPress Bitcoin / AltCoin Payment Gateway for WooCommerce plugin <= 1.7.6 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeSolz Bitcoin / AltCoin Payment Gateway for WooCommerce woo-altcoin-payment-gateway allows Reflected XSS.This issue affects Bitcoin / AltCoin Payment Gateway for WooCommerce: from n/a through <= 1.7.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26541?
CVE-2025-26541 is categorized as a reflected cross-site scripting (XSS) vulnerability, which is considered a medium severity issue.
How do I fix CVE-2025-26541?
To fix CVE-2025-26541, upgrade the Bitcoin / AltCoin Payment Gateway for WooCommerce to version 1.7.7 or later.
Which versions are affected by CVE-2025-26541?
CVE-2025-26541 affects versions from n/a through 1.7.6 of the Bitcoin / AltCoin Payment Gateway for WooCommerce.
What types of attacks can exploit CVE-2025-26541?
CVE-2025-26541 can be exploited through reflected XSS attacks, allowing attackers to inject malicious scripts into web pages.
Is CVE-2025-26541 specific to any platform?
Yes, CVE-2025-26541 specifically affects the Bitcoin / AltCoin Payment Gateway for WooCommerce plugin on WordPress systems.