CVE-2025-23687
Published: 27 February 2025
Summary
CVE-2025-23687 is a high-severity Cross-site Scripting (CWE-79) vulnerability. Its CVSS base score is 7.1 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 32.1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-15 (Information Output Filtering).
Deeper analysis
CVE-2025-23687 is an Improper Neutralization of Input During Web Page Generation vulnerability, enabling Reflected Cross-site Scripting (XSS) as classified under CWE-79. It affects the Woo Store Mode WordPress plugin (woo-store-mode) developed by simonhunter, impacting all versions from n/a through 1.0.1.
The vulnerability carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L), indicating network accessibility, low attack complexity, no required privileges, and user interaction such as visiting a malicious link. Remote attackers can exploit it by tricking authenticated or unauthenticated users into interacting with crafted input reflected in web pages, achieving arbitrary script execution in the victim's browser context with changed scope and low impacts to confidentiality, integrity, and availability.
Patchstack's advisory at https://patchstack.com/database/Wordpress/Plugin/woo-store-mode/vulnerability/wordpress-woo-store-mode-plugin-1-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve details the Reflected XSS issue in Woo Store Mode plugin version 1.0.1 and prior, recommending mitigation through updating to a patched version beyond 1.0.1.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-5450
Vulnerability details
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in simonhunter Woo Store Mode woo-store-mode allows Reflected XSS.This issue affects Woo Store Mode: from n/a through <= 1.0.1.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Reflected XSS in public-facing WordPress plugin directly enables exploitation of public-facing applications (T1190) and arbitrary JavaScript execution in the victim's browser (T1059.007).
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Directly addresses improper neutralization of input during web page generation by filtering output to prevent reflected XSS script execution in the victim's browser.
Validates and sanitizes untrusted input to the Woo Store Mode plugin, blocking malicious payloads before they are reflected in web pages.
Mandates timely identification, reporting, and patching of the XSS flaw in Woo Store Mode versions through 1.0.1 to eliminate the vulnerability.