CVE-2025-48254: WordPress Change Add to Cart Button Text for WooCommerce plugin <= 2.2.2 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Change Add to Cart Button Text for WooCommerce add-to-cart-button-labels-for-woocommerce allows Stored XSS.This issue affects Change Add to Cart Button Text for WooCommerce: from n/a through <= 2.2.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48254?
CVE-2025-48254 is classified as a stored Cross-site Scripting (XSS) vulnerability which can lead to significant security issues.
How do I fix CVE-2025-48254?
To fix CVE-2025-48254, you need to update the Change Add to Cart Button Text for WooCommerce plugin to version 2.2.3 or later.
What types of attacks can CVE-2025-48254 enable?
CVE-2025-48254 can enable attackers to inject malicious scripts into web pages viewed by users, potentially leading to account takeovers and data theft.
Which versions are affected by CVE-2025-48254?
CVE-2025-48254 affects versions of Change Add to Cart Button Text for WooCommerce from 0.0.0 up to and including 2.2.2.
Who is impacted by CVE-2025-48254?
Users of the Change Add to Cart Button Text for WooCommerce plugin versions up to 2.2.2 are impacted by CVE-2025-48254.