Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Upsell Order Bump Offer for WooCommerce allows Stored XSS. This issue affects Upsell Order Bump Offer for WooCommerce: from n/a through 3.0.7.
Metrics
Affected Vendors & Products
Fixes
Solution
Update the WordPress Upsell Order Bump Offer for WooCommerce plugin to the latest available version (at least 3.0.8).
Workaround
No workaround given by the vendor.
References
History
Mon, 22 Sep 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Upsell Order Bump Offer for WooCommerce allows Stored XSS. This issue affects Upsell Order Bump Offer for WooCommerce: from n/a through 3.0.7. | |
Title | WordPress Upsell Order Bump Offer for WooCommerce Plugin <= 3.0.7 - Cross Site Scripting (XSS) Vulnerability | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-09-22T18:26:01.225Z
Reserved: 2025-09-17T18:00:53.704Z
Link: CVE-2025-59565

No data.

Status : Received
Published: 2025-09-22T19:16:24.653
Modified: 2025-09-22T19:16:24.653
Link: CVE-2025-59565

No data.

No data.