CVE-2025-8617
Published
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The YITH WooCommerce Quick View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yith_quick_view shortcode in all versions up to, and including, 2.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
<p><strong>Show a product preview in a modal window to improve your customers’ shopping experience</strong></p>
<p><strong>YITH WooCommerce Quick View</strong> is the free solution to simplify the product viewing and buying process for your customers.<br />
In fact, the plugin allows you to show a preview of your products in a modal window, directly on the shop page.</p>
<p>This way, with just one click, your customers can view available sizes and colors, read product descriptions, and add items to their shopping carts without leaving the catalog. This makes comparing products and purchasing multiple items a quick and easy process.</p>
<p>And thanks to the new 100% mobile friendly design, YITH WooCommerce Quick View also improves the shopping experience for customers who purchase using smartphones and tablets.</p>
<h3>Free version features</h3>
<ul>
<li>Use a text button to preview the product and customize the text</li>
<li>Display the button on the page, below the “Add to cart” button</li>
<li>Enable the Quick View on mobile devices (100% mobile friendly design)</li>
<li>Display the product Quick View in a modal window</li>
<li>Choose if and what description to show (short or long)</li>
<li>Choose the size of the product image</li>
<li>Set the background color of the Quick View</li>
<li>Set the background overlay color</li>
<li>Set the color of the close icon</li>
<li>Set the colors of the “Quick View” button</li>
</ul>
<p>Want to see the plugin in action? Take a look at the <a href="https://plugins.yithemes.com/yith-woocommerce-quick-view-free/" rel="nofollow ugc">live demo of the free version ></a>.</p>
<h3>Need extra features? Upgrade to premium!</h3>
<p>With the free version of YITH WooCommerce Quick View you have everything you need to show a<br />
quick overview of your products and improve the user experience of your shop.<br />
But if you’re looking for advanced options and more versatility, we recommend <strong>upgrading to the premium version</strong> of the plugin.</p>
<h3>Premium version features:</h3>
<ul>
<li>Use a button with an icon</li>
<li>Upload a custom icon for the “Quick View” button</li>
<li>Display the button when hovering over the product image</li>
<li>Use a shortcode or Gutenberg block to allow users to preview a specific product anywhere in your store</li>
<li>Show the product Quick View in a cascading section or in a sidebar</li>
<li>Select an opening animation</li>
<li>Configure modal window height and width</li>
<li>Enable product navigation</li>
<li>Choose which product information to show or hide (image, name, rating, price, “Add to cart” button, etc.)</li>
<li>Choose whether to hide the product image gallery, show it in a classic style, or enable a slider</li>
<li>Display a link to redirect the user to the product detail page</li>
<li>Choose whether to close the Quick View or redirect the user to the Checkout page after adding the product to the cart</li>
<li>Enable social icons to share the product Quick View</li>
<li>Customize the “Add to cart” button</li>
</ul>
<p><a href="https://plugins.yithemes.com/yith-woocommerce-quick-view" rel="nofollow ugc">Check out the live demo of the premium version ></a></p>