Vulnerability in WPFactory Cost of Goods – CVE-2025-48240

Forums Cost of Goods for WooCommerce Vulnerability in WPFactory Cost of Goods – CVE-2025-48240

Viewing 2 posts - 1 through 2 (of 2 total)
  • Author
    Posts
  • #165915
    M
    Participant

    Hi there,

    After noticing the vulnerability alert regarding the Cost of goods for Woocommerce plugin:

    https://www.cve.org/CVERecord?id=CVE-2025-48240

    https://patchstack.com/database/wordpress/plugin/cost-of-goods-for-woocommerce/vulnerability/wordpress-cost-of-goods-for-woocommerce-3-7-0-cross-site-scripting-xss-vulnerability?_s_id=cve

    I checked a couple of sites where the plugin was installed. I saw in both sites the plugins were outdated, and without any trace of update notice, even though several newer versions have been published since the last update. How is this possible? Both sites have an active subscription and are properly licenced.

    Furthermore, as a customer, I would have expected to receive an alert via email about the vulnerability, which, by the way, has been already patched.

    M

    #166211
    Taha
    Moderator
    Plugin Support

    Hi M,

    Thanks for reaching out — I hope you’re doing well. We sincerely apologize for not replying to your message earlier, as it was held in a pending status by the system.

    We also apologize for not updating you about the vulnerability. I’m not sure why you didn’t receive the plugin updates. Could you please confirm whether you’re using the WPFactory Helper plugin, or if you have the new WPFactory menu in your WordPress dashboard?

    If you don’t see the WPFactory menu, please download the plugin again from your account on wpfactory.com, install it on your site, and you should then see the new “WPFactory>Key Manager” menu for managing updates. If you’re still using the old Helper plugin, please deactivate it to avoid any conflicts — that may be why you’re not receiving updates.

    To resolve this more efficiently, I recommend reaching out to us via our support ticket system [email protected]. I’ll personally look into your issue and investigate why updates weren’t delivered. Also, could you kindly share your order ID in your reply?

    Again, we apologize for the inconvenience and appreciate your patience. I’ll be waiting for your confirmation.

    Best regards,
    WPFactory support team

Viewing 2 posts - 1 through 2 (of 2 total)
  • You must be logged in to reply to this topic.