CVE-2022-1465: WPC Smart Wishlist for WooCommerce < 2.9.9 - Reflected Cross-Site Scripting
The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issue.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1465?
CVE-2022-1465 is a vulnerability in the WPC Smart Wishlist for WooCommerce WordPress plugin before version 2.9.9 that can lead to a Reflected Cross-Site Scripting issue.
What is the severity of CVE-2022-1465?
The severity of CVE-2022-1465 is medium with a CVSS score of 6.1.
How does CVE-2022-1465 affect the WPC Smart Wishlist for WooCommerce plugin?
CVE-2022-1465 affects the WPC Smart Wishlist for WooCommerce plugin before version 2.9.9 by allowing an attacker to exploit a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issue.
What is the Common Weakness Enumeration (CWE) for CVE-2022-1465?
The Common Weakness Enumeration (CWE) for CVE-2022-1465 is CWE-79.
How can I fix CVE-2022-1465 in the WPC Smart Wishlist for WooCommerce plugin?
To fix CVE-2022-1465, upgrade to version 2.9.9 or later of the WPC Smart Wishlist for WooCommerce plugin.