CVE-2025-3814
6.4
MediumCVE-2025-3814
•
security@wordfence.com
•
Awaiting Analysis
Description
The Tax Switch for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class-name’ parameter in all versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Exploits
No known exploits found for this CVE.
Search Exploit-DBReferences
security@wordfence.com
https://plugins.trac.wordpress.org/browser/tax-switch-for-woocommerce/tags/1.4.0/includes/class-wdevs-tax-switch-block.php#L112security@wordfence.com
https://plugins.trac.wordpress.org/changeset/3277044/security@wordfence.com
https://wordpress.org/plugins/tax-switch-for-woocommerce/#developers