7.1
CVSSv3

CVE-2025-32524

CVSSv4: NA | CVSSv3: 7.1 | CVSSv2: NA | VMScore: 810 | EPSS: 0.00036 | KEV: Not Included
Published: 11/04/2025 Updated: 11/04/2025

Vulnerability Summary

Reflected Cross-Site Scripting in MyWorks WooCommerce Sync for QuickBooks Online

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyWorks MyWorks WooCommerce Sync for QuickBooks Online allows Reflected XSS. This issue affects MyWorks WooCommerce Sync for QuickBooks Online: from n/a up to and including 2.9.1.

Vulnerable Product Search on Vulmon Subscribe to Product

myworks myworks woocommerce sync for quickbooks online