First published: Tue Feb 21 2023(Updated: )
The Product Slider and Carousel with Category for WooCommerce WordPress plugin before 2.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Essential Plugin Product Slider and Carousel with Category for WooCommerce | <2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4791 has a medium severity rating due to its potential for Stored Cross-Site Scripting vulnerabilities.
To fix CVE-2022-4791, update the Product Slider and Carousel with Category for WooCommerce plugin to version 2.8 or later.
Users with the Product Slider and Carousel with Category for WooCommerce plugin versions prior to 2.8 are affected by CVE-2022-4791.
CVE-2022-4791 can facilitate Stored Cross-Site Scripting attacks, allowing malicious users to inject scripts.
CVE-2022-4791 can be exploited by users with roles as low as contributor.