CVE-2025-48248: WordPress Sitewide Discount for WooCommerce: Apply Discount to All Products plugin <= 2.2.1 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Sitewide Discount for WooCommerce: Apply Discount to All Products allows Stored XSS. This issue affects Sitewide Discount for WooCommerce: Apply Discount to All Products: from n/a through 2.2.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Sitewide Discount for WooCommerce: Apply Discount to All Products global-shop-discount-for-woocommerce allows Stored XSS.This issue affects Sitewide Discount for WooCommerce: Apply Discount to All Products: from n/a through <= 2.2.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48248?
CVE-2025-48248 is considered a critical vulnerability due to its potential for allowing stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-48248?
To fix CVE-2025-48248, update the Sitewide Discount for WooCommerce: Apply Discount to All Products plugin to version 2.2.2 or later.
What type of vulnerability is CVE-2025-48248?
CVE-2025-48248 is classified as a Cross-site Scripting (XSS) vulnerability.
What should I do if I cannot update to the patched version for CVE-2025-48248?
If unable to update, disable the plugin until a secure version is available to mitigate the risk of exploitation from CVE-2025-48248.
Who is affected by CVE-2025-48248?
Users of the WPFactory Sitewide Discount for WooCommerce: Apply Discount to All Products plugin version 2.2.1 and earlier are affected by CVE-2025-48248.