CVE-2023-32575: WordPress Product page shipping calculator for WooCommerce Plugin <= 1.3.25 is vulnerable to Cross Site Scripting (XSS)
Published Aug 25, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Product page shipping calculator for WooCommerce plugin <= 1.3.25 versions.
Affected Software
1 affected component
WooCommerce WooCommerce WordPress<=1.3.25
Remediation
Information
Update to 1.3.26 or a higher version.
Event History
Aug 25, 2023
CVE Published
via MITRE·10:28 AM
Data Sourced
via MITRE·10:28 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of the Auth. (admin+) Stored Cross-Site Scripting vulnerability in PI Websolution Product page shipping calculator for WooCommerce plugin?
The vulnerability ID is CVE-2023-32575.
2
What is the severity of CVE-2023-32575?
The severity of CVE-2023-32575 is medium, with a severity value of 4.8.
3
What software versions are affected by CVE-2023-32575?
The WooCommerce plugin versions up to and including 1.3.25 are affected by CVE-2023-32575.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by an authenticated (admin+) user to inject malicious scripts into the Product page shipping calculator.
5
Is there a fix available for CVE-2023-32575?
Yes, a fix is available for the CVE-2023-32575 vulnerability. Please refer to the provided reference for more information.