CVE-2025-48251: WordPress Additional Custom Emails & Recipients for WooCommerce plugin <= 3.5.1 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Additional Custom Emails & Recipients for WooCommerce custom-emails-for-woocommerce allows Stored XSS.This issue affects Additional Custom Emails & Recipients for WooCommerce: from n/a through <= 3.5.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Additional Custom Emails & Recipients for WooCommerce allows Stored XSS. This issue affects Additional Custom Emails & Recipients for WooCommerce: from n/a through 3.5.1.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48251?
CVE-2025-48251 has a high severity rating due to its potential for stored cross-site scripting exploits.
How do I fix CVE-2025-48251?
To fix CVE-2025-48251, update the Additional Custom Emails & Recipients for WooCommerce plugin to the latest version.
What version of the software is affected by CVE-2025-48251?
CVE-2025-48251 affects versions of the Additional Custom Emails & Recipients for WooCommerce plugin up to 3.5.1.
What type of vulnerability is CVE-2025-48251 classified as?
CVE-2025-48251 is classified as a Cross-site Scripting (XSS) vulnerability.
Who is the vendor associated with CVE-2025-48251?
The vendor associated with CVE-2025-48251 is WPFactory.