Woostify <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lity.js Library via data-lity Attribute in Custom HTML Block
medium
The Woostify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.0 This is due to insufficient input sanitization and output escaping in the bundled Lity.js lightbox library, where user-controlled input from the href attribute is concatenated directly into a jQuery HT...
- CVSS:
- 6.4
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.1
- Disclosed:
- Apr 27, 2026
CVE-2026-4805 on NVD →
Woostify <= 2.4.2 - Authenticated (Shop manager+) Stored Cross-Site Scripting
medium
The Woostify theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 4.4
- Affected:
- up to 2.4.2
- Fixed in:
- 2.5.0
- Disclosed:
- Sep 26, 2025
CVE-2025-60101 on NVD →
Woostify <= 1.9.1 - Cross-Site Request Forgery
high
The Woostify Theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.1. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to add products and edit product quantities in a cart via a forged request...
- CVSS:
- 8.8
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.2
- Disclosed:
- Jun 30, 2021
Woostify [woostify] < 1.9.2
unknown
The Woostify Theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.1. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to add products and edit product quantities in a cart via a forged request...
- Affected:
- up to 1.9.2
- Fixed in:
- 1.9.2
- Disclosed:
- Jun 30, 2021
Woostify [woostify] < 1.9.2
unknown
The theme did not properly check for CSRF, allowing attackers to bypass them and make logged in users add products and edit quantity in their checkout basket
- Affected:
- up to 1.9.2
- Fixed in:
- 1.9.2
Woostify [woostify] <= 2.4.2 (unfixed)
unknown
- Affected:
- up to 2.4.2
- Fix:
- No patched version reported
CVE-2025-60101 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database