CVE-2025-48239: WordPress Product Notes Tab & Private Admin Notes for WooCommerce plugin <= 3.1.0 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product Notes Tab & Private Admin Notes for WooCommerce allows Stored XSS. This issue affects Product Notes Tab & Private Admin Notes for WooCommerce: from n/a through 3.1.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product Notes Tab & Private Admin Notes for WooCommerce product-notes-for-woocommerce allows Stored XSS.This issue affects Product Notes Tab & Private Admin Notes for WooCommerce: from n/a through <= 3.1.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48239?
CVE-2025-48239 is classified as a stored XSS vulnerability, which can lead to serious security issues such as data theft or unauthorized access.
How do I fix CVE-2025-48239?
To fix CVE-2025-48239, update the WPFactory Product Notes Tab & Private Admin Notes for WooCommerce plugin to version 3.1.1 or later.
Which versions of WPFactory Product Notes Tab & Private Admin Notes for WooCommerce are affected by CVE-2025-48239?
CVE-2025-48239 affects all versions of WPFactory Product Notes Tab & Private Admin Notes for WooCommerce up to and including version 3.1.0.
What kind of attacks can CVE-2025-48239 enable?
CVE-2025-48239 can enable malicious users to perform cross-site scripting attacks, potentially compromising user data and site integrity.
Who is responsible for patching CVE-2025-48239?
It is the responsibility of the site administrators using the affected plugin to apply the necessary updates to protect against CVE-2025-48239.