CVE-2025-32552: WordPress MSRP (RRP) Pricing for WooCommerce Plugin <= 1.8.1 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory MSRP (RRP) Pricing for WooCommerce allows Reflected XSS. This issue affects MSRP (RRP) Pricing for WooCommerce: from n/a through 1.8.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory MSRP (RRP) Pricing for WooCommerce msrp-for-woocommerce allows Reflected XSS.This issue affects MSRP (RRP) Pricing for WooCommerce: from n/a through <= 1.8.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32552?
CVE-2025-32552 is considered a reflected Cross-site Scripting (XSS) vulnerability.
How does CVE-2025-32552 affect WPFactory MSRP (RRP) Pricing for WooCommerce?
CVE-2025-32552 allows attackers to inject malicious scripts into web pages viewed by users, impacting the security of the site.
How do I fix CVE-2025-32552?
To fix CVE-2025-32552, upgrade the WPFactory MSRP (RRP) Pricing for WooCommerce plugin to the latest version or at least to version 1.8.2 or higher.
Which versions of WPFactory MSRP (RRP) Pricing for WooCommerce are affected by CVE-2025-32552?
CVE-2025-32552 affects all versions of WPFactory MSRP (RRP) Pricing for WooCommerce from release through version 1.8.1.
What type of attack can be executed via CVE-2025-32552?
CVE-2025-32552 enables attackers to perform reflected XSS attacks, potentially compromising user data and site integrity.