Vulnerability Description
The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its checkout-related AJAX actions, allowing attackers to conduct reflected XSS attacks against logged-in users.
CVSS Score
MEDIUM
References
FAQ
What is CVE-2025-10567?
CVE-2025-10567 is a vulnerability with a CVSS score of 6.3 (MEDIUM). The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its checkout-related AJAX actions, allowing attackers to conduct reflected XSS attacks ag...
How severe is CVE-2025-10567?
CVE-2025-10567 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-10567?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.