CVE-2015-2069: XSS
Published Feb 24, 2015
·Updated
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via the QUERYSTRING in the wc-reports page to wp-admin/admin.php.
Affected Software
1 affected component
Woothemes Woocommerce Wordpress<=2.2.10
Event History
Feb 24, 2015
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2069?
CVE-2015-2069 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2015-2069?
To fix CVE-2015-2069, update the WooCommerce plugin to version 2.2.11 or later.
3
What impact does CVE-2015-2069 have on WordPress sites?
CVE-2015-2069 allows remote attackers to inject malicious scripts into WordPress sites via the QUERY_STRING.
4
Which versions of WooCommerce are affected by CVE-2015-2069?
WooCommerce versions before 2.2.11 are affected by CVE-2015-2069.
5
How can I verify if my site is vulnerable to CVE-2015-2069?
You can verify your site's vulnerability to CVE-2015-2069 by checking the version of the WooCommerce plugin installed.