First published: Thu Nov 16 2023(Updated: )
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in MingoCommerce WooCommerce Product Enquiry plugin <= 2.3.4 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
MingoCommerce WooCommerce Product Enquiry | <=2.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32796 is a vulnerability in the WordPress WooCommerce Product Enquiry Plugin that allows for a Cross-Site Scripting (XSS) attack.
CVE-2023-32796 has a severity rating of 7.1, which is considered high.
CVE-2023-32796 affects MingoCommerce WooCommerce Product Enquiry versions up to and including 2.3.4 by enabling unauthenticated stored Cross-Site Scripting (XSS) attacks.
The CWE ID for CVE-2023-32796 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
To fix CVE-2023-32796, update the MingoCommerce WooCommerce Product Enquiry plugin to a version higher than 2.3.4, as a patch has been released to address this vulnerability.