Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-08320
HistoryJan 06, 2022 - 12:00 a.m.

WordPress Booster for WooCommerce plugin cross-site scripting vulnerability

2022-01-0600:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
wordpress
woocommerce
cross-site scripting

EPSS

0.001

Percentile

43.7%

WordPress is the WordPress Foundation’s suite of blogging platforms developed using the PHP language. A cross-site scripting vulnerability exists in versions of the WordPress Booster for WooCommerce plugin prior to 5.4.9. create_products_xml_result parameter is escaped and filtered, an attacker can use this vulnerability to execute JavaScript code on the client side.

EPSS

0.001

Percentile

43.7%