First published: Thu Apr 17 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product Excel Import Export & Bulk Edit for WooCommerce allows Reflected XSS. This issue affects Product Excel Import Export & Bulk Edit for WooCommerce: from n/a through 4.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPFactory Product Excel Import Export & Bulk Edit for WooCommerce | <=4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32674 has a medium severity level due to its potential for reflected cross-site scripting attacks.
To fix CVE-2025-32674, update the WPFactory Product Excel Import Export & Bulk Edit for WooCommerce to the latest version exceeding 4.7.
Cross-site Scripting in the context of CVE-2025-32674 refers to the improper handling of user input that could allow an attacker to inject malicious scripts into web pages.
CVE-2025-32674 can compromise website security by allowing attackers to execute arbitrary scripts in the context of a user’s session.
Users of WPFactory Product Excel Import Export & Bulk Edit for WooCommerce versions from any up to 4.7 are affected by CVE-2025-32674.