Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3005 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes Free WooCommerce Theme 99fy Extension allows Stored XSS.This issue affects Free WooCommerce Theme 99fy Extension: from n/a through 1.2.8. |
Solution
Update the WordPress Free WooCommerce Theme 99fy Extension wordpress plugin to the latest available version (at least 1.2.9).
Workaround
No workaround given by the vendor.
Fri, 10 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Jan 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes Free WooCommerce Theme 99fy Extension allows Stored XSS.This issue affects Free WooCommerce Theme 99fy Extension: from n/a through 1.2.8. | |
| Title | WordPress Free WooCommerce Theme 99fy Extension plugin <= 1.2.8 - Cross Site Scripting (XSS) vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-01-10T20:41:51.405Z
Reserved: 2025-01-07T21:05:34.184Z
Link: CVE-2025-22801
Updated: 2025-01-10T20:18:27.755Z
Status : Received
Published: 2025-01-09T16:16:29.323
Modified: 2025-01-09T16:16:29.323
Link: CVE-2025-22801
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:19Z
EUVD