CVE-2014-6313: XSS
Published Oct 14, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the range parameter on the wc-reports page to wp-admin/admin.php.
Affected Software
16 affected components
Woothemes Woocommerce Plugin Wordpress<=2.2.2
Woothemes Woocommerce Plugin Wordpress=2.1.0
Woothemes Woocommerce Plugin Wordpress=2.1.1
Woothemes Woocommerce Plugin Wordpress=2.1.2
Woothemes Woocommerce Plugin Wordpress=2.1.3
Woothemes Woocommerce Plugin Wordpress=2.1.4
Woothemes Woocommerce Plugin Wordpress=2.1.5
Woothemes Woocommerce Plugin Wordpress=2.1.6
Woothemes Woocommerce Plugin Wordpress=2.1.7
Woothemes Woocommerce Plugin Wordpress=2.1.8
Woothemes Woocommerce Plugin Wordpress=2.1.9
Woothemes Woocommerce Plugin Wordpress=2.1.10
Woothemes Woocommerce Plugin Wordpress=2.1.11
Woothemes Woocommerce Plugin Wordpress=2.1.12
Woothemes Woocommerce Plugin Wordpress=2.2.0
Woothemes Woocommerce Plugin Wordpress=2.2.1
Event History
Oct 14, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6313?
CVE-2014-6313 is considered a medium severity vulnerability due to its ability to allow remote attackers to execute arbitrary scripts.
2
How do I fix CVE-2014-6313?
To fix CVE-2014-6313, update the WooCommerce plugin to version 2.2.3 or later.
3
What versions are affected by CVE-2014-6313?
CVE-2014-6313 affects all WooCommerce plugin versions prior to 2.2.3.
4
Can CVE-2014-6313 be exploited without user interaction?
Yes, CVE-2014-6313 can be exploited remotely without user interaction through crafted requests.
5
What is the nature of the vulnerability in CVE-2014-6313?
CVE-2014-6313 is a cross-site scripting (XSS) vulnerability that allows for the injection of arbitrary web scripts or HTML.