CVE-2025-57963: WordPress Zoho Billing Plugin <= 4.1 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Subscriptions Zoho Billing allows DOM-Based XSS. This issue affects Zoho Billing: from n/a through 4.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Subscriptions Zoho Billing zoho-subscriptions allows DOM-Based XSS.This issue affects Zoho Billing: from n/a through <= 4.1.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57963?
CVE-2025-57963 is categorized as a moderate severity vulnerability due to its potential for causing cross-site scripting (XSS) attacks.
How do I fix CVE-2025-57963?
To fix CVE-2025-57963, update Zoho Subscriptions or Zoho Billing to the latest version that addresses the XSS vulnerability.
Which versions of Zoho Billing are affected by CVE-2025-57963?
CVE-2025-57963 affects all versions of Zoho Billing from n/a through 4.1.
Does CVE-2025-57963 affect any WordPress plugins?
Yes, CVE-2025-57963 also affects the WordPress Zoho Billing Plugin up to version 4.1.
What type of vulnerability is CVE-2025-57963?
CVE-2025-57963 is a DOM-based cross-site scripting (XSS) vulnerability.