CVE-2025-48253: WordPress Free Shipping Bar: Amount Left for Free Shipping for WooCommerce plugin <= 2.4.6 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Free Shipping Bar: Amount Left for Free Shipping for WooCommerce amount-left-free-shipping-woocommerce allows Stored XSS.This issue affects Free Shipping Bar: Amount Left for Free Shipping for WooCommerce: from n/a through <= 2.4.6.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48253?
CVE-2025-48253 has a high severity rating due to its potential to allow stored cross-site scripting attacks.
How do I fix CVE-2025-48253?
To fix CVE-2025-48253, you should update the Free Shipping Bar: Amount Left for Free Shipping for WooCommerce plugin to version 2.4.7 or later.
What are the potential impacts of CVE-2025-48253?
The potential impacts of CVE-2025-48253 include unauthorized data access and manipulation, as well as compromising user sessions through stored XSS.
Which versions of the Free Shipping Bar plugin are affected by CVE-2025-48253?
CVE-2025-48253 affects Free Shipping Bar: Amount Left for Free Shipping for WooCommerce versions up to and including 2.4.6.
Is CVE-2025-48253 specific to any particular platform?
Yes, CVE-2025-48253 specifically affects the WordPress platform through the Free Shipping Bar: Amount Left for Free Shipping for WooCommerce plugin.