First published: Mon Jul 11 2022(Updated: )
The WooCommerce - Product Importer WordPress plugin through 1.5.2 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Visser Woocommerce - Product Importer | <=1.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of the WooCommerce - Product Importer WordPress plugin is CVE-2022-1546.
The severity of CVE-2022-1546 is medium with a CVSS score of 6.1.
The affected software for CVE-2022-1546 is the WooCommerce - Product Importer WordPress plugin version up to 1.5.2.
The CWE category for CVE-2022-1546 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
To fix the vulnerability, update the WooCommerce - Product Importer WordPress plugin to version 1.5.3 or later.