CVE-2023-22705: WordPress Welcart e-Commerce Plugin <= 2.8.10 is vulnerable to Cross Site Scripting (XSS)
Published Mar 29, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Collne Inc. Welcart e-Commerce plugin <= 2.8.10 versions.
Affected Software
2 affected components
Collne Welcart E-commerce Wordpress<=2.8.10
Welcart Welcart e-Commerce WordPress<=2.8.10
Remediation
Information
Update to 2.8.11 or a higher version.
Event History
Mar 29, 2023
CVE Published
via MITRE·07:32 PM
Data Sourced
via MITRE·07:32 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-22705?
The severity of CVE-2023-22705 is high.
2
What is the affected software version of CVE-2023-22705?
The affected software version of CVE-2023-22705 is <= 2.8.10.
3
What is the CWE of CVE-2023-22705?
The CWE of CVE-2023-22705 is CWE-79 (Cross-Site Scripting).
4
How can I fix CVE-2023-22705?
To fix CVE-2023-22705, update the Collne Inc. Welcart e-Commerce plugin to a version above 2.8.10.
5
Where can I find more information about CVE-2023-22705?
You can find more information about CVE-2023-22705 at https://patchstack.com/database/vulnerability/usc-e-shop/wordpress-welcart-e-commerce-plugin-2-8-10-cross-site-scripting-xss-vulnerability?_s_id=cve