Project Subscriptions
No advisories yet.
Solution
Update the WordPress WooCommerce plugin to the latest available version (at least 10.0.3).
Workaround
No workaround given by the vendor.
Tue, 20 Jan 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 20 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:automattic:woocommerce:*:*:*:*:*:*:*:* | |
| References |
|
Wed, 29 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Oct 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Automattic
Automattic woocommerce Wordpress Wordpress wordpress |
|
| Vendors & Products |
Automattic
Automattic woocommerce Wordpress Wordpress wordpress |
Wed, 29 Oct 2025 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce woocommerce allows Stored XSS.This issue affects WooCommerce: from n/a through 10.0.2. | |
| Title | WordPress WooCommerce plugin <= 10.0.2 - Cross Site Scripting (XSS) vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-01-20T14:28:06.098Z
Reserved: 2025-05-30T14:04:26.750Z
Link: CVE-2025-49042
Updated: 2025-10-29T13:31:14.856Z
Status : Awaiting Analysis
Published: 2025-10-29T05:15:37.080
Modified: 2026-01-20T15:16:31.663
Link: CVE-2025-49042
No data.
OpenCVE Enrichment
Updated: 2025-10-29T10:57:34Z