CVE-2025-32539: WordPress WooCommerce – Store Exporter plugin <= 2.7.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Kohlbach Store Exporter woocommerce-exporter allows Reflected XSS.This issue affects Store Exporter: from n/a through <= 2.7.4.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Kohlbach WooCommerce – Store Exporter allows Reflected XSS. This issue affects WooCommerce – Store Exporter: from n/a through 2.7.4.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32539?
CVE-2025-32539 has a severity rating that indicates a significant risk due to the possibility of reflected cross-site scripting (XSS) attacks.
How does CVE-2025-32539 affect WooCommerce – Store Exporter?
CVE-2025-32539 allows reflected XSS, which can enable attackers to execute arbitrary JavaScript in the context of affected users.
Which versions of WooCommerce – Store Exporter are affected by CVE-2025-32539?
CVE-2025-32539 affects WooCommerce – Store Exporter versions up to and including 2.7.4.
What are the potential consequences of CVE-2025-32539?
Exploitation of CVE-2025-32539 can lead to information leakage, session hijacking, and other malicious actions performed in a user's browser.
How do I fix CVE-2025-32539?
To fix CVE-2025-32539, update the WooCommerce – Store Exporter to the latest version that addresses the XSS vulnerability.