CVE-2025-47505
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ProWCPlugins Product Time Countdown for WooCommerce product-countdown-for-woocommerce allows Stored XSS.This issue affects Product Time Countdown for WooCommerce: from n/a through <= 1.6.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in Product Time Countdown for WooCommerce plugin allows privileged attackers to inject malicious scripts.
Vulnerability
Description Product Time Countdown for WooCommerce (versions up to 1.6.2) suffers from a stored cross-site scripting (XSS) vulnerability. The plugin fails to properly neutralize user input during web page generation, enabling attackers to inject arbitrary scripts into the site [1].
Exploitation
Exploitation requires a user with contributor-level privileges or higher. An attacker with such access can inject malicious payloads into product pages or countdown fields. These payloads are subsequently executed when other users, including administrators, view the affected pages [1].
Impact
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser. This can lead to session hijacking, defacement, redirection to malicious sites, or theft of sensitive information [1]. The vulnerability has a CVSS score of 6.5 (Medium), indicating moderate severity.
Mitigation
The vulnerability is patched in version 1.6.3. Users are strongly advised to update to this version immediately. For those unable to update, a full security review and input sanitization should be applied [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<= 1.6.2+ 1 more
- (no CPE)range: <= 1.6.2
- (no CPE)range: <=1.6.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.