First published: Mon May 16 2022(Updated: )
The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issue.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpclever WPC Smart Wishlist for WooCommerce | <2.9.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1465 is a vulnerability in the WPC Smart Wishlist for WooCommerce WordPress plugin before version 2.9.9 that can lead to a Reflected Cross-Site Scripting issue.
The severity of CVE-2022-1465 is medium with a CVSS score of 6.1.
CVE-2022-1465 affects the WPC Smart Wishlist for WooCommerce plugin before version 2.9.9 by allowing an attacker to exploit a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issue.
The Common Weakness Enumeration (CWE) for CVE-2022-1465 is CWE-79.
To fix CVE-2022-1465, upgrade to version 2.9.9 or later of the WPC Smart Wishlist for WooCommerce plugin.