🔐 CVE Alert

CVE-2025-23550

UNKNOWN 0.0

WordPress Product Puller plugin <= 1.5.1 - Reflected Cross Site Scripting (XSS) vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kemal YAZICI Product Puller product-puller allows Reflected XSS.This issue affects Product Puller: from n/a through <= 1.5.1.

CWE CWE-79
Vendor kemal yazici
Product product puller
Published Dec 29, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for kemal yazici product puller

Be the first to know when new unknown vulnerabilities affecting kemal yazici product puller are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Kemal YAZICI / Product Puller
0 ≤ 1.5.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/product-puller/vulnerability/wordpress-product-puller-plugin-1-5-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve

Credits

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program