Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themebon Easy Woocommerce Customizer easy-woocommerce-customizer allows Reflected XSS.This issue affects Easy Woocommerce Customizer: from n/a through <= 1.0.2.
Published: 2025-10-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The identified flaw allows a Reflected Cross‑Site Scripting (XSS) attack in the WordPress Easy Woocommerce Customizer plugin. The vulnerability stems from inadequate neutralization of user input during page rendering, classifying it as a CWE‑79 weakness. Exploitation can cause an attacker’s script to run in the victim’s browser, potentially leading to session hijacking, credential theft, or defacement of the site.

Affected Systems

Any WordPress installation that includes themebon Easy Woocommerce Customizer plugin version 1.0.2 or earlier is affected. The vulnerability is active across all unsupported releases from the earliest version up to and including 1.0.2, impacting sites that have not applied the subsequent update.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium severity level. EPSS < 1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the nature of the flaw, the likely attack vector is via a crafted URL or form input that is reflected back in the generated page, allowing an attacker to deliver malicious scripts to unsuspecting users. The impact is confined to client‑side execution and does not provide direct remote code execution on the server.

Generated by OpenCVE AI on April 29, 2026 at 23:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Easy Woocommerce Customizer to the latest release that supersedes 1.0.2, which contains proper input sanitization.
  • Apply strict input validation and output encoding to any data rendered by the plugin, following CWE‑79 best practices.
  • Implement or strengthen a Content Security Policy that blocks inline scripts, thereby reducing the effectiveness of any residual XSS vectors.

Generated by OpenCVE AI on April 29, 2026 at 23:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Themebon
Themebon easy Woocommerce Customizer
Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Themebon
Themebon easy Woocommerce Customizer
Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themebon Easy Woocommerce Customizer easy-woocommerce-customizer allows Reflected XSS.This issue affects Easy Woocommerce Customizer: from n/a through <= 1.0.2.
Title WordPress Easy Woocommerce Customizer plugin <= 1.0.2 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Themebon Easy Woocommerce Customizer
Woocommerce Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:51.229Z

Reserved: 2025-09-06T04:45:39.391Z

Link: CVE-2025-59006

cve-icon Vulnrichment

Updated: 2025-10-23T13:38:08.494Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:53.587

Modified: 2026-04-27T20:16:23.840

Link: CVE-2025-59006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T23:45:16Z

Weaknesses