VYPR
Medium severity6.5NVD Advisory· Published Sep 26, 2025· Updated Apr 23, 2026

CVE-2025-58917

CVE-2025-58917

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick Verwymeren Quantities and Units for WooCommerce quantities-and-units-for-woocommerce allows Stored XSS.This issue affects Quantities and Units for WooCommerce: from n/a through <= 1.0.13.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in WordPress Quantities and Units for WooCommerce plugin (≤1.0.13) allows authenticated attackers to inject malicious scripts.

The Quantities and Units for WooCommerce plugin for WordPress versions 1.0.13 and earlier contains a stored cross-site scripting (XSS) vulnerability due to improper neutralization of input during web page generation. This flaw allows an attacker to inject arbitrary web scripts into pages that will be executed whenever a user accesses the affected page [1].

Exploitation requires at least a privileged user role (e.g., Shop Manager) to perform an action, such as submitting a form or clicking a crafted link. The injected script is stored on the server, meaning the attack does not require user interaction by the victim beyond visiting the page where the payload resides. The vulnerability is classified with a CVSS v3 score of 6.5, reflecting medium severity [1].

The impact includes the ability for an attacker to inject malicious scripts, which could be used to redirect visitors to phishing sites, display unauthorized advertisements, or alter page content. Such stored XSS attacks can compromise the integrity of the website and may lead to further exploitation of site visitors [1].

Users are strongly advised to update the plugin to a patched version as soon as possible. If an immediate update is not possible, consulting a hosting provider or web developer for additional security measures is recommended. The vulnerability is actively used in mass-exploit campaigns, underscoring the need for prompt action [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.