CVE-2025-22801: Hasthemes Free Woocommerce Theme 99fy Extension

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes Free WooCommerce Theme 99fy Extension 99fy-core allows Stored XSS.This issue affects Free WooCommerce Theme 99fy Extension: from n/a through <= 1.2.8.

Affected products

  • Hasthemes Free Woocommerce Theme 99fy Extension: up to and including 1.2.8

Published 2025-01-09. Last modified 2026-06-17.