CVE-2022-1916: Active Products Tables for WooCommerce < 1.0.5 - Reflected Cross-Site-Scripting
The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected cross-Site Scripting
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1916?
CVE-2022-1916 is a vulnerability in the Active Products Tables for WooCommerce WordPress plugin that allows for unauthenticated and authenticated users to execute malicious code.
What is the severity of CVE-2022-1916?
The severity of CVE-2022-1916 is medium (6.1).
How does CVE-2022-1916 affect the Active Products Tables for WooCommerce plugin?
CVE-2022-1916 affects the Active Products Tables for WooCommerce plugin version up to 1.0.5, allowing for the execution of malicious code.
How can I fix CVE-2022-1916?
To fix CVE-2022-1916, it is recommended to update the Active Products Tables for WooCommerce plugin to a version beyond 1.0.5.
Where can I find more information about CVE-2022-1916?
You can find more information about CVE-2022-1916 at the following reference: [https://wpscan.com/vulnerability/d16a0c3d-4318-4ecd-9e65-fc4165af8808]