Lucene search

K
wpvulndbAlex SanfordWPVDB-ID:1187E041-3BE2-4613-8D56-C2394FCC75FB
HistoryMay 01, 2023 - 12:00 a.m.

Product Addons & Fields for WooCommerce < 32.0.7 - Reflected Cross-Site Scripting

2023-05-0100:00:00
Alex Sanford
wpscan.com
26
woocommerce
reflected cross-site scripting
security issue
url parameters
plugin

EPSS

0.001

Percentile

31.2%

The plugin does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.

PoC

Ensure WooCommerce is installed. Visit the following path, while logged in as an Admin: /wp-admin/admin.php?page=ppom&productmeta;_id=5&do;_meta=edit&">=1

EPSS

0.001

Percentile

31.2%

Related for WPVDB-ID:1187E041-3BE2-4613-8D56-C2394FCC75FB