CVE-2023-0079: Customer Reviews for WooCommerce < 5.17.0 - Contributor+ Stored XSS
The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0079?
CVE-2023-0079 is considered a high-severity vulnerability due to its potential for Stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2023-0079?
To fix CVE-2023-0079, update the Customer Reviews for WooCommerce plugin to version 5.17.0 or later.
Who is affected by CVE-2023-0079?
CVE-2023-0079 affects sites using the Customer Reviews for WooCommerce WordPress plugin versions prior to 5.17.0.
What types of attacks can CVE-2023-0079 allow?
CVE-2023-0079 can allow attackers with contributor roles or higher to perform Stored Cross-Site Scripting (XSS) attacks.
What are the consequences of not addressing CVE-2023-0079?
Failing to address CVE-2023-0079 can lead to unauthorized access or manipulation of site content through XSS attacks.