CVE-2025-49305: WordPress Product Catalog Simple plugin <= 1.8.1 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode Product Catalog Simple allows Stored XSS. This issue affects Product Catalog Simple: from n/a through 1.8.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode Product Catalog Simple post-type-x allows Stored XSS.This issue affects Product Catalog Simple: from n/a through <= 1.8.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49305?
CVE-2025-49305 is considered a medium severity vulnerability due to its potential for Stored XSS attacks.
How do I fix CVE-2025-49305?
To fix CVE-2025-49305, update Implecode Product Catalog Simple to version 1.8.2 or later.
What type of vulnerability is CVE-2025-49305?
CVE-2025-49305 is a Cross-site Scripting (XSS) vulnerability related to improper input neutralization.
Which versions of Product Catalog Simple are affected by CVE-2025-49305?
CVE-2025-49305 affects Implecode Product Catalog Simple versions from n/a up to and including 1.8.1.
Can CVE-2025-49305 lead to data breaches?
Yes, CVE-2025-49305 could potentially lead to data breaches by allowing attackers to execute malicious scripts.