CVE-2023-0537: Product Slider For WooCommerce Lite <= 1.1.7 - Contributor+ Stored XSS
The Product Slider For WooCommerce Lite WordPress plugin through 1.1.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-0537?
CVE-2023-0537 is a vulnerability in the Product Slider For WooCommerce Lite WordPress plugin that allows users with the contributor role and above to perform Stored Cross-Site Scripting (XSS) attacks.
How severe is CVE-2023-0537?
CVE-2023-0537 has a severity score of 5.4, which is considered medium.
What software is affected by CVE-2023-0537?
The Product Slider For WooCommerce Lite WordPress plugin versions up to and including 1.1.7 are affected by CVE-2023-0537.
How can I fix CVE-2023-0537?
To fix CVE-2023-0537, update the Product Slider For WooCommerce Lite WordPress plugin to a version higher than 1.1.7.
Where can I find more information about CVE-2023-0537?
More information about CVE-2023-0537 can be found at this reference link: [https://wpscan.com/vulnerability/d7369f1d-d1a0-4576-a676-c70525a6c743]