CVE-2023-2256: Product Addons & Fields for WooCommerce < 32.0.7 - Reflected Cross-Site Scripting
Published May 30, 2023
·Updated
The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.
Affected Software
1 affected component
Themeisle Product Addons \& Fields For Woocommerce Wordpress<32.0.7
Event History
May 30, 2023
CVE Published
via MITRE·07:49 AM
Data Sourced
via MITRE·07:49 AM
DescriptionWeakness
Data Sourced
08:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-2256.
2
What is the severity rating of CVE-2023-2256?
CVE-2023-2256 has a severity rating of 6.1 (medium).
3
What is the affected software?
The affected software is the Product Addons & Fields for WooCommerce WordPress plugin version up to 32.0.7.
4
What does CVE-2023-2256 vulnerability allow?
CVE-2023-2256 allows for Reflected Cross-Site Scripting.
5
How can I fix CVE-2023-2256 vulnerability?
To fix CVE-2023-2256 vulnerability, update the Product Addons & Fields for WooCommerce WordPress plugin to version 32.0.7 or higher.