CVE-2025-39446: WordPress Booster Plus for WooCommerce plugin <= 7.2.4 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl LLC Booster Plus for WooCommerce allows Reflected XSS.This issue affects Booster Plus for WooCommerce: from n/a through 7.2.4.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl LLC Booster Plus for WooCommerce booster-plus-for-woocommerce allows Reflected XSS.This issue affects Booster Plus for WooCommerce: from n/a through <= 7.2.4.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39446?
CVE-2025-39446 is classified as a high-severity vulnerability due to its potential for exploitation via reflected cross-site scripting.
How do I fix CVE-2025-39446?
To fix CVE-2025-39446, update the Booster Plus for WooCommerce plugin to version 7.2.5 or later.
What type of vulnerability is CVE-2025-39446?
CVE-2025-39446 is a reflected cross-site scripting (XSS) vulnerability.
Which versions of Booster Plus for WooCommerce are affected by CVE-2025-39446?
CVE-2025-39446 affects Booster Plus for WooCommerce versions up to and including 7.2.4.
Who is the vendor affected by CVE-2025-39446?
The vendor affected by CVE-2025-39446 is Pluggabl LLC.