CVE-2025-47600: WordPress WoodMart theme <= 8.3.7 - Arbitrary Shortcode Execution vulnerability
Published Jan 22, 2026
·Updated
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in xtemos WoodMart woodmart allows Code Injection.This issue affects WoodMart: from n/a through <= 8.3.7.
Affected Software
1 affected component
Xtemos WoodMart<=8.3.7
Event History
Jan 22, 2026
CVE Published
via MITRE·04:51 PM
Data Sourced
via MITRE·04:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-47600?
CVE-2025-47600 has been rated as a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2025-47600?
To fix CVE-2025-47600, update the WoodMart theme to version 8.3.8 or later.
3
What impact does CVE-2025-47600 have on my website?
CVE-2025-47600 can allow attackers to execute arbitrary shortcodes, leading to unauthorized code execution and potential site compromise.
4
Which versions of WoodMart are affected by CVE-2025-47600?
CVE-2025-47600 affects all WoodMart theme versions from n/a up to and including 8.3.7.
5
Is CVE-2025-47600 an XSS vulnerability?
Yes, CVE-2025-47600 is classified as a Basic XSS vulnerability due to its improper neutralization of script-related HTML tags.