CVE-2023-25049: WordPress eCommerce Product Catalog Plugin <= 3.3.4 is vulnerable to Cross Site Scripting (XSS)
Published Apr 7, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress plugin <= 3.3.4 versions.
Affected Software
1 affected component
impleCode Ecommerce Product Catalog Wordpress<=3.3.4
Remediation
Information
Update to 3.3.5 or a higher version.
Event History
Apr 7, 2023
CVE Published
via MITRE·11:12 AM
Data Sourced
via MITRE·11:12 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-25049?
The severity of CVE-2023-25049 is medium with a score of 4.8.
2
How does CVE-2023-25049 affect Implecode eCommerce Product Catalog Plugin for WordPress?
CVE-2023-25049 affects Implecode eCommerce Product Catalog Plugin for WordPress versions up to and including 3.3.4.
3
What is the CWE of CVE-2023-25049?
The CWE of CVE-2023-25049 is CWE-79.
4
Are there any references for CVE-2023-25049?
Yes, you can find references for CVE-2023-25049 at [this link](https://patchstack.com/database/vulnerability/ecommerce-product-catalog/wordpress-ecommerce-product-catalog-plugin-for-wordpress-plugin-3-3-4-cross-site-scripting-xss-vulnerability?_s_id=cve).
5
How can I fix the Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Implecode eCommerce Product Catalog Plugin for WordPress?
To fix the vulnerability, update Implecode eCommerce Product Catalog Plugin for WordPress to a version above 3.3.4.