Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-68539
HistoryJan 05, 2022 - 12:00 a.m.

WordPress plugin Booster for WooCommerce cross-site scripting vulnerability

2022-01-0500:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
wordpress
woocommerce
cross-site scripting
vulnerability
php
filtering
escaping
administration page
authentication credentials
cookie-based

EPSS

0.001

Percentile

43.7%

WordPress is a set of blogging platform developed using the PHP language. A cross-site scripting vulnerability exists in the WordPress plugin Booster for WooCommerce. The vulnerability stems from the program not filtering and escaping the wcj_delete_role parameter before exporting it back to the administration page. An attacker could use this vulnerability to steal cookie-based authentication credentials.

EPSS

0.001

Percentile

43.7%