First published: Wed Jan 04 2017(Updated: )
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WooCommerce | <=2.6.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10112 is considered a high severity cross-site scripting vulnerability.
To fix CVE-2016-10112, update the WooCommerce plugin to version 2.6.9 or later.
CVE-2016-10112 affects remote authenticated administrators using WooCommerce versions prior to 2.6.9.
The potential impact of CVE-2016-10112 includes the ability for attackers to inject arbitrary web scripts or HTML.
You can determine if your site is vulnerable by checking if you are using a version of the WooCommerce plugin older than 2.6.9.