CVE-2018-20966: XSS
Published Aug 12, 2019
·Updated
The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.
Affected Software
1 affected component
Booster Booster for WooCommerce WordPress<3.8.0
Event History
Aug 12, 2019
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2018-20966.
2
What is the severity of CVE-2018-20966?
The severity of CVE-2018-20966 is medium with a CVSS score of 6.1.
3
Which plugin is affected by CVE-2018-20966?
The woocommerce-jetpack plugin before version 3.8.0 for WordPress is affected by CVE-2018-20966.
4
Which feature of the woocommerce-jetpack plugin is vulnerable to XSS?
The Products Per Page feature of the woocommerce-jetpack plugin is vulnerable to XSS.
5
How can I fix CVE-2018-20966?
To fix CVE-2018-20966, update the woocommerce-jetpack plugin to version 3.8.0 or later.