Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendons WooCommerce Registration Fields Plugin - Custom Signup Fields extendons-registration-fields allows Reflected XSS.This issue affects WooCommerce Registration Fields Plugin - Custom Signup Fields: from n/a through <= 3.2.3.
Published: 2025-10-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The extendons WooCommerce Registration Fields Plugin – Custom Signup Fields contains a reflected Cross‑Site Scripting flaw caused by uncontrolled output of user input when generating registration pages. Attackers can craft input that is echoed back to the browser, allowing arbitrary JavaScript to run in the context of the site visitor’s browser. This can enable session hijacking, cookie theft, and malicious actions performed under the victim’s authority. The vulnerability is a classic injection weakness identified as CWE‑79.

Affected Systems

Any WordPress installation that uses the extendons WooCommerce Registration Fields Plugin – Custom Signup Fields, from the earliest release through version 3.2.3, is affected. No further version details are supplied, so all instances of the plugin at or below 3.2.3 must be considered vulnerable.

Risk and Exploitability

The flaw has a CVSS base score of 7.1 and an extremely low EPSS (< 1%), indicating that while the potential damage is significant, the likelihood of widespread exploitation is presently low. The vulnerability is not listed in CISA’s KEV catalogue. Exploitation requires a victim to load a maliciously crafted registration form or URL, which an attacker can easily embed in links or webpages. Given the client‑side nature of the flaw, any authenticated or unauthenticated user pointing the browser at a tainted input field could trigger the payload.

Generated by OpenCVE AI on April 29, 2026 at 23:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade extendons WooCommerce Registration Fields Plugin to the latest available version or remove the plugin if an upgrade is unavailable
  • Sanitize and escape all custom registration field inputs before rendering them in HTML output to ensure any injected scripts are neutralized
  • Implement a Content Security Policy (CSP) that disallows inline scripts and restricts script sources to trusted domains

Generated by OpenCVE AI on April 29, 2026 at 23:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 23 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Extendons
Extendons woocommerce Registration Fields Plugin
Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Extendons
Extendons woocommerce Registration Fields Plugin
Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendons WooCommerce Registration Fields Plugin - Custom Signup Fields extendons-registration-fields allows Reflected XSS.This issue affects WooCommerce Registration Fields Plugin - Custom Signup Fields: from n/a through <= 3.2.3.
Title WordPress WooCommerce Registration Fields Plugin - Custom Signup Fields plugin <= 3.2.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Extendons Woocommerce Registration Fields Plugin
Woocommerce Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:27:33.892Z

Reserved: 2025-06-11T16:07:27.324Z

Link: CVE-2025-49947

cve-icon Vulnrichment

Updated: 2025-10-23T14:42:40.371Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:40.963

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-49947

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T23:45:16Z

Weaknesses