First published: Tue May 30 2023(Updated: )
The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Themeisle PPOM for WooCommerce | <32.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-2256.
CVE-2023-2256 has a severity rating of 6.1 (medium).
The affected software is the Product Addons & Fields for WooCommerce WordPress plugin version up to 32.0.7.
CVE-2023-2256 allows for Reflected Cross-Site Scripting.
To fix CVE-2023-2256 vulnerability, update the Product Addons & Fields for WooCommerce WordPress plugin to version 32.0.7 or higher.