Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product Excel Import Export & Bulk Edit for WooCommerce webd-woocommerce-product-excel-importer-bulk-edit allows Reflected XSS.This issue affects Product Excel Import Export & Bulk Edit for WooCommerce: from n/a through <= 4.7.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a reflected cross‑site scripting flaw where the plugin fails to neutralize malicious input before rendering it in a browser. This weakness, identified as CWE‑79, allows an attacker to inject arbitrary client‑side scripts into pages served to users of the WordPress site. When triggered, the injected script can execute in the victim’s browser context, potentially leading to cookie theft, session hijacking, defacement, or diffusion of other malicious payloads. The impact is confined to the scope of the affected plugin and the user browsing the affected pages, but it can compromise any user who views the compromised output, including administrators and visitors.

Affected Systems

The flaw affects the WordPress plugin Product Excel Import Export & Bulk Edit for WooCommerce developed by WPFactory. Versions from the initial release through 4.7 are known to be vulnerable. Any WordPress installation that has this plugin installed and enabled in these versions is susceptible unless mitigated by an update or other controls.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity for this reflected XSS flaw, while the EPSS score of less than 1% suggests it is currently considered a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Distinguishing a clear attack vector requires an attacker to supply crafted input that is echoed by the plugin; this can typically be carried out by sending a malicious link or submitting a form that contains the vulnerable parameter. The likelihood of exploitation remains contingent on the plugin’s usability and exposure to public access.

Generated by OpenCVE AI on April 30, 2026 at 22:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Product Excel Import Export & Bulk Edit for WooCommerce plugin to version 4.8 or newer to remove the reflected XSS flaw.
  • If an immediate update is not possible, disable the plugin or restrict its use to trusted administrative accounts only to prevent exposure to malicious input.
  • Implement a content security policy that disallows inline scripts or privileged script execution in the domain to mitigate the impact of any remaining reflected XSS until a patch is applied.

Generated by OpenCVE AI on April 30, 2026 at 22:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11733 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product Excel Import Export & Bulk Edit for WooCommerce allows Reflected XSS. This issue affects Product Excel Import Export & Bulk Edit for WooCommerce: from n/a through 4.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product Excel Import Export & Bulk Edit for WooCommerce allows Reflected XSS. This issue affects Product Excel Import Export & Bulk Edit for WooCommerce: from n/a through 4.7. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product Excel Import Export & Bulk Edit for WooCommerce webd-woocommerce-product-excel-importer-bulk-edit allows Reflected XSS.This issue affects Product Excel Import Export & Bulk Edit for WooCommerce: from n/a through <= 4.7.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product Excel Import Export & Bulk Edit for WooCommerce allows Reflected XSS. This issue affects Product Excel Import Export & Bulk Edit for WooCommerce: from n/a through 4.7.
Title WordPress Product Excel Import Export & Bulk Edit for WooCommerce plugin <= 4.7 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:27.937Z

Reserved: 2025-04-09T11:21:18.307Z

Link: CVE-2025-32674

cve-icon Vulnrichment

Updated: 2025-04-17T18:08:57.243Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:50.480

Modified: 2026-04-23T15:29:19.623

Link: CVE-2025-32674

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T22:15:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')