CVE-2016-10112: XSS
Published Jan 4, 2017
·Updated
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.
Affected Software
1 affected component
WooCommerce WooCommerce WordPress<=2.6.8
Event History
Jan 4, 2017
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10112?
CVE-2016-10112 is considered a high severity cross-site scripting vulnerability.
2
How do I fix CVE-2016-10112?
To fix CVE-2016-10112, update the WooCommerce plugin to version 2.6.9 or later.
3
Who is affected by CVE-2016-10112?
CVE-2016-10112 affects remote authenticated administrators using WooCommerce versions prior to 2.6.9.
4
What are the potential impacts of CVE-2016-10112?
The potential impact of CVE-2016-10112 includes the ability for attackers to inject arbitrary web scripts or HTML.
5
How can I determine if my site is vulnerable to CVE-2016-10112?
You can determine if your site is vulnerable by checking if you are using a version of the WooCommerce plugin older than 2.6.9.