CVE-2025-64289: WordPress Premmerce Product Search for WooCommerce plugin <= 2.2.7 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows Stored XSS.This issue affects Premmerce Product Search for WooCommerce: from n/a through 2.2.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64289?
CVE-2025-64289 is classified as a high severity vulnerability due to its potential for stored cross-site scripting attacks.
What software is affected by CVE-2025-64289?
CVE-2025-64289 affects versions of Premmerce Product Search for WooCommerce up to and including 2.2.4.
How do I fix CVE-2025-64289?
To fix CVE-2025-64289, update Premmerce Product Search for WooCommerce to the latest version available that resolves this vulnerability.
What type of vulnerability is CVE-2025-64289?
CVE-2025-64289 is a stored cross-site scripting (XSS) vulnerability.
Can CVE-2025-64289 lead to data theft?
Yes, CVE-2025-64289 can potentially allow attackers to steal sensitive user information through malicious scripts.