Lucene search

K
wpvulndbErwan LR (WPscan)WPVDB-ID:4992A4A9-F21A-46E2-BABF-954ACFC7C5B4
HistoryJan 08, 2024 - 12:00 a.m.

Product Enquiry for WooCommerce < 3.2 - Reflected XSS

2024-01-0800:00:00
Erwan LR (WPscan)
wpscan.com
7
woocommerce
plugin
xss
attribute
admin
risk
security

EPSS

0.001

Percentile

17.0%

Description The plugin does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PoC

Make a logged in admin open a page with the code below

EPSS

0.001

Percentile

17.0%

Related for WPVDB-ID:4992A4A9-F21A-46E2-BABF-954ACFC7C5B4