cleantalk
Vulnerabilities and Security Researches

Order Status Rules for WooCommerce, CVE-2025-30781

CVE, Research URL

CVE-2025-30781

Published on
Mar 27, 2025
Research Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WPFactory Scheduled & Automatic Order Status Controller for WooCommerce allows Phishing. This issue affects Scheduled & Automatic Order Status Controller for WooCommerce: from n/a through 3.7.1.
Affected versions
Min -, max 3.7.2.
Status
vulnerable