Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes Free WooCommerce Theme 99fy Extension 99fy-core allows Stored XSS.This issue affects Free WooCommerce Theme 99fy Extension: from n/a through <= 1.2.8.

INFO

Published Date :

2025-01-09T15:39:21.237Z

Last Modified :

2026-04-01T15:41:52.907Z

Source :

Patchstack
AFFECTED PRODUCTS

The following products are affected by CVE-2025-22801 vulnerability.

Vendors Products
Hasthemes
  • Free Woocommerce Theme 99fy Extension
Wordpress
  • Wordpress
REFERENCES

CVSS Vulnerability Scoring System