CVE-2025-47615: WordPress Amazon Product in a Post plugin <= 5.2.2 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flowdee Amazon Product in a Post allows Stored XSS. This issue affects Amazon Product in a Post: from n/a through 5.2.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flowdee Amazon Product in a Post amazon-product-in-a-post-plugin allows Stored XSS.This issue affects Amazon Product in a Post: from n/a through <= 5.2.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47615?
CVE-2025-47615 is a high severity vulnerability due to its potential to enable Stored Cross-site Scripting (XSS).
How do I fix CVE-2025-47615?
To fix CVE-2025-47615, update the Amazon Product in a Post plugin to version 5.2.3 or later.
What systems are affected by CVE-2025-47615?
CVE-2025-47615 affects the Amazon Product in a Post plugin for WordPress versions up to and including 5.2.2.
What type of vulnerability is CVE-2025-47615?
CVE-2025-47615 is classified as a Cross-site Scripting (XSS) vulnerability.
Can CVE-2025-47615 lead to data breaches?
Yes, CVE-2025-47615 can potentially allow attackers to execute malicious scripts, leading to data breaches.