CVE-2025-64200
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Email Template Customizer for WooCommerce email-template-customizer-for-woo allows Stored XSS.This issue affects Email Template Customizer for WooCommerce: from n/a through <= 1.2.17.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in VillaTheme Email Template Customizer for WooCommerce (<=1.2.17) allows attackers to inject malicious scripts via email templates, requiring admin interaction to trigger.
Vulnerability
Overview
CVE-2025-64200 is a Stored Cross-Site Scripting (XSS) vulnerability found in the VillaTheme Email Template Customizer for WooCommerce plugin, affecting all versions up to and including 1.2.17. The root cause is improper neutralization of user-supplied input during web page generation, which enables an attacker to store arbitrary JavaScript code within the email template content [1].
Exploitation
Conditions
To exploit this flaw, an attacker must have at least an account with the ability to edit email templates (typically a Shop Manager or Administrator role). The injected malicious script is then stored on the server and executed when any user (including site visitors) views the affected email. However, successful exploitation requires a privileged user to perform an action, such as clicking a malicious link or previewing a crafted template [1].
Impact
An attacker can inject scripts that perform a variety of malicious actions, including redirecting users to phishing pages, displaying unwanted advertisements, or stealing sensitive session cookies. This can lead to compromised site integrity, unauthorized data access, and potential account takeovers [1].
Mitigation
The vulnerability has been patched in version 1.2.18. Users are strongly advised to update immediately. For those unable to update, the advisory notes that the plugin is part of mass-exploit campaigns, and contacting a hosting provider or web developer for assistance is recommended. Patchstack users can enable auto-updates for vulnerable plugins [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.2.17
- Range: <=1.2.17
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.