CVE-2023-0166: PickPlugins Product Slider for WooCommerce < 1.13.42 - Contributor+ Stored XSS
The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-0166.
What is the title of this vulnerability?
The title of this vulnerability is 'The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate ...'
What is the severity of CVE-2023-0166?
The severity of CVE-2023-0166 is medium with a CVSS score of 5.4.
Which software is affected by this vulnerability?
The 'PickPlugins Product Slider for WooCommerce WordPress' plugin version up to 1.13.42 is affected by this vulnerability.
How can this vulnerability be exploited?
This vulnerability can be exploited by users with the contributor role and above to perform Stored Cross-Site Scripting (XSS) attacks.