CVE-2025-69088

WordPress Combo Offers WooCommerce plugin <= 4.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vidish Combo Offers WooCommerce woo-combo-offers allows DOM-Based XSS.This issue affects Combo Offers WooCommerce: from n/a through <= 4.2.


We have discovered 319 live websites that are affected by CVE-2025-69088.

Run a Free Instant Scan




Affected Software

Product  Woo Combo Offers
Category Wordpress Plugins
Vulnerable Domains319 live websites (75% of Woo Combo Offers install base)
Vulnerable Versions
  • from 0 through 4.2
Vulnerable Versions Count12 versions ( 86% of all versions)



Details

  • Published - Dec 30, 2025
  • Updated - Jan 20, 2026

Credits

  • Muhammad Yudha - DJ | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2025-69088
United States59 websites



Brazil51 websites
India26 websites
Netherlands23 websites
South Africa22 websites
GB14 websites
Vietnam12 websites
Germany12 websites
France8 websites
Cyprus7 websites

Website Distribution by TLD

Number of websites using CVE-2025-69088
.com114 websites
.com.br47 websites
.nl23 websites
.co.uk8 websites
.ca4 websites
.ch4 websites
.org4 websites
.it4 websites
.ru3 websites
.fr3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-69088

Top websites that are affected by CVE-2025-69088. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****************.com India*,***,***
*********.com Portugal*,***,***
***************.vn Vietnam*,***,***
**************.***.br Brazil*,***,***
********.**.uk GB*,***,***
********.***.br Brazil*,***,***
*****************.nl Netherlands*,***,***
******.***.ar Argentina*,***,***
***********.com United States*,***,***
***********.com United States*,***,***
See full domain list

FAQ

A total of 319 websites have been identified as vulnerable to CVE-2025-69088, based on global website indexing conducted by WebTechSurvey.
The Woo Combo Offers is affected by the CVE-2025-69088 vulnerability.
Woo Combo Offers versions up to and including 4.2 are vulnerable to CVE-2025-69088.