CVE-2025-47592

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lehel Mtyus Legal Terms and Conditions Popup for User Login and WooCommerce Checkout  TPUL allows Stored XSS. This issue affects Legal Terms and Conditions Popup for User Login and WooCommerce Checkout  TPUL: from n/a through 2.0.3.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
PatchstackCNA
5.9 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
CISA-ADPADP
---
---