CVE-2025-39579: WordPress Membership For WooCommerce plugin <= 2.8.0 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Membership For WooCommerce allows DOM-Based XSS. This issue affects Membership For WooCommerce: from n/a through 2.8.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows DOM-Based XSS.This issue affects Membership For WooCommerce: from n/a through <= 2.8.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39579?
CVE-2025-39579 has a moderate severity level, as it allows DOM-Based XSS which can lead to unauthorized actions or data exposure.
How do I fix CVE-2025-39579?
To fix CVE-2025-39579, upgrade the Membership For WooCommerce plugin to version 2.8.1 or later.
What software is affected by CVE-2025-39579?
CVE-2025-39579 affects the Membership For WooCommerce plugin, version 2.8.0 and earlier.
What type of vulnerability is CVE-2025-39579?
CVE-2025-39579 is classified as a cross-site scripting (XSS) vulnerability due to improper input neutralization.
Can CVE-2025-39579 be exploited remotely?
Yes, CVE-2025-39579 can be exploited remotely by an attacker to execute malicious scripts in the context of the user's browser.