Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.1
RVCFDI Para Woocommerce allows malicious scripts to run on your website.
CVE-2025-69386
Summary
An attacker can inject malicious code into your website, potentially stealing sensitive information or taking control of your site. This affects RVCFDI Para Woocommerce plugins installed on your WordPress site. Update to version 8.1.9 or later to fix the issue.
Original title
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realvirtualmx RVCFDI para Woocommerce rvcfdi-para-woocommerce allows Reflected XSS.This issue a...
Original description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realvirtualmx RVCFDI para Woocommerce rvcfdi-para-woocommerce allows Reflected XSS.This issue affects RVCFDI para Woocommerce: from n/a through <= 8.1.8.
nvd CVSS3.1
7.1
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 20 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026