CVE-2023-1839: Product Addons & Fields for WooCommerce < 32.0.6 - Admin+ Stored Cross-Site Scripting
The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.6 does not sanitize and escape some of its setting fields, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example, in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-1839.
What is the severity of CVE-2023-1839?
The severity of CVE-2023-1839 is medium with a severity value of 4.8.
How does CVE-2023-1839 impact the Product Addons & Fields for WooCommerce WordPress plugin?
CVE-2023-1839 allows high-privilege users, such as admin, to perform Stored Cross-Site Scripting attacks by exploiting unsanitized and unescaped setting fields in the plugin.
What is the affected version of the Product Addons & Fields for WooCommerce WordPress plugin?
The affected version of the Product Addons & Fields for WooCommerce WordPress plugin is before 32.0.6.
How can the vulnerability in CVE-2023-1839 be fixed?
To fix the vulnerability in CVE-2023-1839, users should update the Product Addons & Fields for WooCommerce WordPress plugin to version 32.0.6 or later.