PT-2025-17532 · Pluggabl Llc+2 · Booster Plus For Woocommerce+2

Trương Hữu Phúc

·

Published

2025-04-22

·

Updated

2025-05-19

·

CVE-2025-39446

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Booster Plus for WooCommerce versions through 7.2.4
Description: The issue affects the Booster Plus for WooCommerce plugin, allowing for Reflected XSS due to improper neutralization of input during web page generation. This can lead to cross-site scripting attacks.
Recommendations: For Booster Plus for WooCommerce versions through 7.2.4, update to a version later than 7.2.4 to resolve the issue. As a temporary workaround, consider restricting user input in web page generation to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-39446

Affected Products

Booster Plus For Woocommerce
Booster For Woocommerce
Woocommerce-Jetpack