CVE-2025-62096: WordPress Maximum Products per User for WooCommerce plugin <= 4.4.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Maximum Products per User for WooCommerce allows Stored XSS.This issue affects Maximum Products per User for WooCommerce: from n/a through 4.4.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Maximum Products per User for WooCommerce maximum-products-per-user-for-woocommerce allows Stored XSS.This issue affects Maximum Products per User for WooCommerce: from n/a through <= 4.4.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62096?
CVE-2025-62096 is classified as a Stored XSS vulnerability, which can have a high severity impact on affected sites.
How do I fix CVE-2025-62096?
To fix CVE-2025-62096, update the Maximum Products per User for WooCommerce plugin to the latest version.
What versions are affected by CVE-2025-62096?
CVE-2025-62096 affects the Maximum Products per User for WooCommerce plugin versions from n/a through 4.4.2.
What are the implications of CVE-2025-62096 on my website?
The implications of CVE-2025-62096 include potential unauthorized access to user data and malicious actions on your website due to stored XSS.
Is CVE-2025-62096 easily exploitable?
Yes, CVE-2025-62096 is easily exploitable, as it allows attackers to inject malicious scripts that can affect users visiting the website.