Lucene search

K
wpvulndbWpvulndbWPVDB-ID:C63F4F09-79EC-492A-840E-80F3EAC6917A
HistoryMay 01, 2023 - 12:00 a.m.

Advanced Woo Search < 2.78 - Admin+ Stored Cross-Site Scripting

2023-05-0100:00:00
wpscan.com
2
advanced woo search
version 2.78
admin settings
stored cross-site scripting
vulnerability
multi-site installations
unfiltered_html disabled
software

EPSS

0.001

Percentile

45.1%

The plugin does not properly sanitize input and escape output in admin settings, leading to Stored Cross-Site Scripting vulnerabilities. This issue affects multi-site installations and those with unfiltered_html disabled.

EPSS

0.001

Percentile

45.1%

Related for WPVDB-ID:C63F4F09-79EC-492A-840E-80F3EAC6917A