CVE-2025-22337
Published: 13 January 2025
Summary
CVE-2025-22337 is a high-severity Cross-site Scripting (CWE-79) vulnerability. Its CVSS base score is 7.1 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 30.5th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-15 (Information Output Filtering).
Deeper analysis
CVE-2025-22337 is an Improper Neutralization of Input During Web Page Generation vulnerability, enabling Reflected Cross-site Scripting (XSS) as classified under CWE-79. It affects the Order Audit Log for WooCommerce WordPress plugin developed by infosoftplugin, with the issue present in all versions from n/a through 2.0 inclusive.
The vulnerability carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L), indicating exploitation is possible over the network with low attack complexity, no privileges required, and user interaction such as clicking a malicious link. Attackers can achieve low impacts on confidentiality, integrity, and availability with a changed scope, typically allowing execution of arbitrary scripts in the victim's browser context to steal session data or perform other client-side actions.
The Patchstack advisory at https://patchstack.com/database/Wordpress/Plugin/order-audit-log-for-woocommerce/vulnerability/wordpress-order-audit-log-for-woocommerce-plugin-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve provides details on this Reflected XSS issue in plugin version 2.0 and associated mitigation guidance for affected WordPress installations.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-2737
Vulnerability details
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in infosoftplugin Order Audit Log for WooCommerce order-audit-log-for-woocommerce allows Reflected XSS.This issue affects Order Audit Log for WooCommerce: from n/a through <= 2.0.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Reflected XSS in public-facing WordPress plugin directly enables web app exploitation (T1190) and arbitrary JavaScript execution in victim browser (T1059.007).
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Directly prevents reflected XSS by requiring filtering and encoding of user inputs prior to inclusion in dynamically generated web pages.
Mitigates the vulnerability by validating and sanitizing untrusted inputs to block XSS payloads before processing in the WooCommerce plugin.
Addresses the CVE by mandating timely identification, reporting, and patching of the flawed Order Audit Log plugin versions.