cve/2025/CVE-2025-24657.md
2025-09-29 21:09:30 +02:00

833 B

CVE-2025-24657

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee Wishlist for WooCommerce allows Stored XSS. This issue affects Wishlist for WooCommerce: from n/a through 2.1.2.

POC

Reference

No PoCs from references.

Github