CVE-2025-49042

WordPress WooCommerce plugin <= 10.0.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce woocommerce allows Stored XSS.This issue affects WooCommerce: from n/a through <= 10.0.2.


We have discovered 442,462 live websites that are affected by CVE-2025-49042.

Run a Free Instant Scan




Affected Software

Product  WooCommerce
Category Ecommerce
Vulnerable Domains442,462 live websites (35% of WooCommerce install base)
Vulnerable Versions
  • from 0 through 10.0.2
Vulnerable Versions Count461 versions ( 91% of all versions)



Details

  • Published - Oct 29, 2025
  • Updated - Apr 28, 2026

Credits

  • savphill | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2025-49042
United States98,084 websites



Germany33,124 websites
France23,779 websites
Italy22,730 websites
GB21,336 websites
Russia18,809 websites
Spain16,158 websites
Vietnam14,855 websites
Netherlands12,868 websites
Poland11,872 websites

Website Distribution by TLD

Number of websites using CVE-2025-49042
.com188,862 websites
.it15,695 websites
.ru14,892 websites
.de13,543 websites
.co.uk12,513 websites
.org11,035 websites
.nl10,742 websites
.pl8,870 websites
.fr8,688 websites
.net8,218 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-49042

Top websites that are affected by CVE-2025-49042. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.com United States*,***
***********.com United States*,***
***********.com Germany*,***
***********.com Singapore*,***
*****************.com United States*,***
*************.com United States*,***
**********.com Czech Republic*,***
*********.com United States*,***
**********.com United States*,***
***************.org Israel**,***
See full domain list

FAQ

A total of 442,462 websites have been identified as vulnerable to CVE-2025-49042, based on global website indexing conducted by WebTechSurvey.
The WooCommerce is affected by the CVE-2025-49042 vulnerability.
WooCommerce versions up to and including 10.0.2 are vulnerable to CVE-2025-49042.