CVE-2025-58228: WordPress Quick View for WooCommerce Plugin <= 2.2.16 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC Quick View for WooCommerce allows Stored XSS. This issue affects Quick View for WooCommerce: from n/a through 2.2.16.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC Quick View for WooCommerce woo-quickview allows Stored XSS.This issue affects Quick View for WooCommerce: from n/a through <= 2.2.16.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58228?
CVE-2025-58228 is categorized as a stored Cross-site Scripting (XSS) vulnerability that can lead to significant security issues for affected users.
How do I fix CVE-2025-58228?
To fix CVE-2025-58228, you should update Quick View for WooCommerce to the latest version that addresses this vulnerability.
Which versions are affected by CVE-2025-58228?
CVE-2025-58228 affects Quick View for WooCommerce versions from n/a through 2.2.16.
What impact does CVE-2025-58228 have on my website?
CVE-2025-58228 can allow attackers to execute malicious scripts on your website, compromising user data and site security.
Who is responsible for the CVE-2025-58228 vulnerability?
The CVE-2025-58228 vulnerability is identified in the Quick View for WooCommerce plugin developed by ShapedPlugin LLC.