CVE-2021-25043: WOOCS < 1.3.7.3 - Reflected Cross-Site Scripting
Published Jan 10, 2022
·Updated
The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the customprices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue
Affected Software
1 affected component
Pluginus Woocommerce Currency Switcher Wordpress<1.3.7.3
Remediation
Event History
Jan 10, 2022
CVE Published
via MITRE·03:30 PM
Data Sourced
via MITRE·03:30 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-25043.
2
What is the affected software?
The affected software is the WOOCS WordPress plugin before version 1.3.7.3.
3
What is the severity of CVE-2021-25043?
The severity of CVE-2021-25043 is medium (CVSS score: 6.1).
4
What is the CWE category of this vulnerability?
The CWE category for CVE-2021-25043 is CWE-79 (Cross-Site Scripting).
5
How do I fix CVE-2021-25043?
To fix CVE-2021-25043, update the WOOCS WordPress plugin to version 1.3.7.3 or later.