CVE-2022-1532: Themify - WooCommerce Product Filter < 1.3.8 - Reflected Cross-Site Scripting
Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1532?
CVE-2022-1532 is categorized as a medium severity vulnerability due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2022-1532?
To fix CVE-2022-1532, update the Themify Woocommerce Product Filter plugin to version 1.3.8 or later.
What types of attacks can CVE-2022-1532 facilitate?
CVE-2022-1532 can facilitate reflected cross-site scripting attacks that could compromise user sessions or steal sensitive data.
Which versions of the Themify Woocommerce Product Filter are affected by CVE-2022-1532?
CVE-2022-1532 affects all versions of the Themify Woocommerce Product Filter plugin prior to version 1.3.8.
Is CVE-2022-1532 specific to the WordPress platform?
Yes, CVE-2022-1532 specifically impacts the Themify Woocommerce Product Filter plugin within the WordPress platform.