CVE-2025-47570: WordPress WooCommerce Photo Reviews plugin <= 1.3.13 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooCommerce Photo Reviews woocommerce-photo-reviews.This issue affects WooCommerce Photo Reviews: from n/a through <= 1.3.13.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooCommerce Photo Reviews. This issue affects WooCommerce Photo Reviews: from n/a through 1.3.13.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47570?
CVE-2025-47570 is classified as a Cross-site Scripting (XSS) vulnerability that can lead to significant security risks.
How do I fix CVE-2025-47570?
To fix CVE-2025-47570, update the WooCommerce Photo Reviews plugin to a version later than 1.3.13.
What software is affected by CVE-2025-47570?
CVE-2025-47570 affects the Villatheme and WordPress versions of the WooCommerce Photo Reviews plugin up to version 1.3.13.
What are the consequences of CVE-2025-47570?
Exploitation of CVE-2025-47570 can allow an attacker to execute malicious scripts in the context of users' browsers.
Who is responsible for fixing CVE-2025-47570?
The responsibility for fixing CVE-2025-47570 lies with users of the affected WooCommerce Photo Reviews plugin, who should apply updates promptly.