CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
Percentile
31.7%
The Booster for WooCommerce WordPress plugin before 5.6.3, Booster Plus for WooCommerce WordPress plugin before 6.0.0, Booster Elite for WooCommerce WordPress plugin before 6.0.0 do not escape some URLs and parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting
Vendor | Product | Version | CPE |
---|---|---|---|
booster | booster_elite_for_woocommerce | * | cpe:2.3:a:booster:booster_elite_for_woocommerce:*:*:*:*:*:wordpress:*:* |
booster | booster_for_woocommerce | * | cpe:2.3:a:booster:booster_for_woocommerce:*:*:*:*:*:wordpress:*:* |
booster | booster_plus_for_woocommerce | * | cpe:2.3:a:booster:booster_plus_for_woocommerce:*:*:*:*:*:wordpress:*:* |
[
{
"vendor": "Unknown",
"product": "Booster for WooCommerce",
"versions": [
{
"status": "affected",
"versionType": "custom",
"version": "0",
"lessThan": "5.6.3"
}
],
"defaultStatus": "unaffected",
"collectionURL": "https://wordpress.org/plugins"
},
{
"vendor": "Unknown",
"product": "Booster Plus for WooCommerce",
"versions": [
{
"status": "affected",
"versionType": "custom",
"version": "0",
"lessThan": "6.0.0"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Unknown",
"product": "Booster Elite for WooCommerce",
"versions": [
{
"status": "affected",
"versionType": "custom",
"version": "0",
"lessThan": "6.0.0"
}
],
"defaultStatus": "unaffected"
}
]