Skip to main content
A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Find Out Why
  • Experiencing a breach?
  • Blog
  • Careers
  • Platform & Products

    • Singularity™ Platform

      Unified Enterprise Security. Machine-Speed Protection, Intelligence, and Response.

    • XDR

      Native and Open Protection, Detection, and Response.

    • Integrations and Partners

      One-Click Integrations to Unlock the Power of SentinelOne.

    Product Tours
    Pricing & Packages
    Get a Demo
  • Solutions & Use Cases

    SentinelOne for Industries

    Security Tuned for Your Industry.

    See All Industries
    • Healthcare

      Protect Patient Data. Keep Clinical Systems Online.

    • Financial Services

      Stop Fraud and Ransomware. Stay Audit-Ready.

    • Federal Government

      FedRAMP and IL5-Ready Defense for Federal Missions.

    • Manufacturing

      Defend OT, IT, IIOT, and Supply Chains at Scale.

    • Energy

      Secure OT Systems and Critical Infrastructure.

    • Transportation and Logistics

      Defend Operations Across Fleet, Port, and Rail.

    • Higher Education

      Protect Open Networks Without Slowing Research.

    • K-12 Education

      Stop Ransomware. Protect Students, Staff, and Data.

    • Retail and Hospitality

      Defend Your Brand, Customer Data, and Bottom Line.

    • SMB & Startups

      Enterprise-Grade Defense for Fast Teams.

    See all solutions
  • Services

    Managed Services

    Wayfinder Threat Detection and Response.

    Learn More
    • Threat Hunting

      World-Class Expertise and Threat Intelligence.

    • Managed Detection and Response

      24/7 Expert MDR Across Your Entire Environment.

    • Incident Readiness and Response

      DFIR, Breach Readiness, and Compromise Assessments.

    Experiencing a breach?

    Our experts are here to help 24/7.

    1-855-868-3733
    Get Help Now
  • Partners

    Become a Partner

    • Become a SentinelOne Partner

      Join the Global SentinelOne Ecosystem

    • Explore MSSP Solutions

      Services Succeed Faster with SentinelOne

    • Form a Technology Alliance

      Integrated, Enterprise-Scale Solutions

    Find a Partner

    • Enlist a Response or Advisory Team

      Enlist Pro Response and Advisory Teams

    • SentinelOne for AWS

      Hosted Across AWS Regions Worldwide

    • SentinelOne for Google

      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale

    • Partner Locator

      Your Go-to Source for Our Top Partners in Your Region

    • Singularity Marketplace

      One-Click Integrations for Unified Prevention, Detection, and Response

      Explore integrations
    Partner Portal Login
  • Why SentinelOne

    • Why Choose SentinelOne

      AI-Powered Cybersecurity Built to Secure What’s Next.

    • Our Customers

      Trusted by the World’s Leading Companies.

    • Industry Awards & Recognition

      Tested and Proven by the Experts.

  • Resources & Support

    Resources

    • Resource Center
    • Webinars
    • Cybersecurity Blog
    • Events
    • Newsroom

    Company

    • About SentinelOne
    • Careers
    • S Ventures
    • S Foundation
    • Dataset
    • FAQ
    • Investors Relations

    Customer Success & Support

    • Live and On-Demand Training
    • Guided Onboarding & Deployment
    • Technical Account Management
    • Support Services
    • Customer Portal
    • Get Support Now

    Explore

    • Vulnerability Database
    • SentinelLABS Threat Research
    • Ransomeware Anthology
    • Cybersecurity 101
    EventJoin us at OneCon (Oct. 20–22, 2026)
    CompetitionThreat Hunting World Championship 2026
    ReportThe SentinelOne Annual Threat Report
  • Pricing
Get StartedContact us

Explore SentinelOne

  • Pricing
Events
Get StartedContact us
CVE Vulnerability Database
Vulnerability Database/CVE-2025-22335

CVE-2025-22335: OpenCart Product in WP XSS Vulnerability

CVE-2025-22335 is a reflected cross-site scripting flaw in the OpenCart Product in WP plugin that allows attackers to inject malicious scripts. This article covers the technical details, affected versions, and mitigation.

Published: April 29, 2026

CVE-2025-22335 Overview

A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Opencart Product in WP WordPress plugin developed by rajib.dewan. This vulnerability allows attackers to inject malicious scripts through crafted URLs, which are then executed in the context of a victim's browser session when they click on the malicious link. The vulnerability stems from improper neutralization of input during web page generation (CWE-79).

Critical Impact

Attackers can execute arbitrary JavaScript in the context of authenticated user sessions, potentially leading to session hijacking, credential theft, website defacement, or phishing attacks targeting WordPress administrators and site visitors.

Affected Products

  • Opencart Product in WP plugin versions up to and including 1.0.1
  • WordPress installations with the vulnerable plugin installed
  • Sites using the opencart-product-in-wp plugin for OpenCart integration

Discovery Timeline

  • 2025-01-07 - CVE-2025-22335 published to NVD
  • 2026-04-23 - Last updated in NVD database

Technical Details for CVE-2025-22335

Vulnerability Analysis

This Reflected XSS vulnerability occurs when user-supplied input is improperly sanitized before being rendered in the browser. The Opencart Product in WP plugin fails to adequately neutralize special characters and HTML entities in user input, allowing attackers to inject executable JavaScript code into web pages served by the affected WordPress site.

Reflected XSS attacks require user interaction—typically clicking on a malicious link crafted by an attacker. When a victim clicks the link, the malicious script embedded in the URL parameter is reflected back by the server and executed in the victim's browser. This can result in cookie theft, session hijacking, keylogging, or redirecting users to malicious websites.

The attack requires no prior privileges on the system and can be executed remotely over the network, though user interaction is required for successful exploitation.

Root Cause

The root cause of this vulnerability is insufficient input validation and output encoding within the Opencart Product in WP plugin. The plugin fails to properly sanitize user-controlled data before including it in HTTP responses. WordPress provides several built-in functions for escaping output such as esc_html(), esc_attr(), and wp_kses(), but these safeguards were not properly implemented in the affected code paths.

Attack Vector

The attack vector for CVE-2025-22335 is network-based and requires user interaction. An attacker crafts a malicious URL containing JavaScript payload in a vulnerable parameter. The attack flow typically involves:

  1. The attacker identifies a vulnerable parameter in the Opencart Product in WP plugin
  2. A malicious URL is crafted containing an XSS payload in that parameter
  3. The victim is socially engineered to click the malicious link (via phishing, social media, etc.)
  4. When clicked, the WordPress site reflects the malicious input back to the browser
  5. The victim's browser executes the injected JavaScript in the context of the WordPress site
  6. The attacker gains the ability to perform actions as the victim, steal session cookies, or redirect to malicious sites

The vulnerability does not require authentication, making any visitor to the site a potential target. However, targeting authenticated administrators could yield higher impact results such as full site compromise.

Detection Methods for CVE-2025-22335

Indicators of Compromise

  • Suspicious URL parameters containing encoded JavaScript payloads (e.g., <script>, javascript:, onerror=)
  • Web server logs showing requests with unusual encoded characters or script tags in query strings
  • User reports of unexpected browser behavior or redirects when visiting specific plugin-related URLs
  • Browser console errors indicating blocked inline script execution (if CSP is enabled)

Detection Strategies

  • Implement Web Application Firewall (WAF) rules to detect and block common XSS payloads in request parameters
  • Monitor web server access logs for suspicious patterns including encoded script tags and event handlers
  • Deploy browser-based detection using Content Security Policy (CSP) violation reporting
  • Use automated vulnerability scanners to periodically test WordPress installations for XSS vulnerabilities

Monitoring Recommendations

  • Enable detailed logging on WordPress installations and review logs for abnormal request patterns
  • Configure CSP headers with report-uri directive to receive reports of policy violations
  • Implement real-time alerting for patterns matching known XSS attack signatures
  • Monitor for unauthorized plugin modifications or unexpected changes to plugin files

How to Mitigate CVE-2025-22335

Immediate Actions Required

  • Deactivate and remove the Opencart Product in WP plugin immediately if not critical to operations
  • Implement a Web Application Firewall (WAF) with XSS protection rules as an interim measure
  • Enable Content Security Policy (CSP) headers to mitigate the impact of potential XSS exploitation
  • Review WordPress user accounts for any signs of unauthorized access or suspicious activity

Patch Information

As of the last NVD update, versions through 1.0.1 remain affected. Site administrators should check the Patchstack WordPress Vulnerability Report for the latest information regarding patches or updated versions. If no patch is available, consider removing the plugin or implementing compensating controls.

Contact the plugin developer (rajib.dewan) through the WordPress plugin directory for information on remediation timelines.

Workarounds

  • Remove or deactivate the opencart-product-in-wp plugin until a patched version is available
  • Implement strict Content Security Policy headers to block inline script execution
  • Deploy a WAF rule to filter requests containing XSS patterns targeting the affected plugin endpoints
  • Consider using an alternative OpenCart integration solution that is actively maintained
bash
# WordPress CLI command to deactivate the vulnerable plugin
wp plugin deactivate opencart-product-in-wp

# Add Content Security Policy header in .htaccess (Apache)
# Header set Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none';"

# Verify plugin status after deactivation
wp plugin list --status=active

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeXSS

  • Vendor/TechOpencart Product In Wp

  • SeverityHIGH

  • CVSS Score7.1

  • EPSS Probability0.23%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityLow
  • AvailabilityLow
  • CWE References
  • CWE-79
  • Technical References
  • Patchstack WordPress Vulnerability Report
  • Latest CVEs
  • CVE-2026-50263: X.org X Server Use-After-Free Flaw

  • CVE-2026-21033: Samsung Assistant RCE Vulnerability

  • CVE-2026-21032: Samsung Assistant RCE Vulnerability

  • CVE-2026-50260: X.org X Server Use-After-Free Flaw
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
Get a DemoContact Us
  • Product Tours
  • Why SentinelOne
  • Pricing & Packages
  • FAQ
  • SentinelOne Status

Key Products & Solutions

  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Prompt Security
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Explore Solutions

Services

  • Wayfinder TDR
  • Managed Detection and Response
  • Threat Hunting
  • Incident Readiness
& Response
  • Technical Account Management
  • Guided Onboarding 
& Deployment
  • Support Services

Company

  • About Us
  • Our Customers
  • Careers
  • Partners
  • S1 Foundation
  • S1 Ventures
  • Legal Information
  • Security & Compliance
  • Investor Relations

Quick Links

  • Customer Portal
  • Partner Portal
  • Become a Partner
  • Resource Center
  • SentinelLABS Threat Research
  • Blog
  • Press Center
  • Cybersecurity 101
  • Events
  • Ransomware Anthology
©2026 SentinelOne, All Rights Reserved
Privacy NoticeTerms of Use
English
English