CVE-2025-31598: WordPress Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin <= 4.0.3 - Stored Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Quantity Dynamic Pricing & Bulk Discounts for WooCommerce wholesale-pricing-woocommerce allows Stored XSS.This issue affects Quantity Dynamic Pricing & Bulk Discounts for WooCommerce: from n/a through <= 4.0.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31598?
CVE-2025-31598 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS).
How do I fix CVE-2025-31598?
To fix CVE-2025-31598, update the WPFactory Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin to version 4.0.1 or newer.
What are the effects of CVE-2025-31598?
CVE-2025-31598 allows attackers to inject malicious scripts into web pages, potentially compromising user data and site integrity.
Which versions of WPFactory Quantity Dynamic Pricing & Bulk Discounts for WooCommerce are affected by CVE-2025-31598?
CVE-2025-31598 affects all versions of the WPFactory Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin up to and including version 4.0.0.
Is CVE-2025-31598 easy to exploit?
Yes, CVE-2025-31598 is considered relatively easy to exploit, making it critical for users to apply necessary patches promptly.