CVE-2025-49911: WordPress WooCommerce Vehicle Parts Finder plugin <= 3.7 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Reflected XSS.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49911?
CVE-2025-49911 is classified as a moderate severity Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2025-49911?
To fix CVE-2025-49911, upgrade WooCommerce Vehicle Parts Finder to a version higher than 3.7.
What impact does CVE-2025-49911 have on my site?
CVE-2025-49911 allows attackers to execute scripts in the context of the affected user's browser, potentially compromising sensitive information.
Which versions of WooCommerce Vehicle Parts Finder are affected by CVE-2025-49911?
CVE-2025-49911 affects all versions of WooCommerce Vehicle Parts Finder up to and including version 3.7.
Is CVE-2025-49911 a reflected XSS vulnerability?
Yes, CVE-2025-49911 is a reflected XSS vulnerability that can be exploited to inject malicious scripts.