First published: Wed Aug 30 2023(Updated: )
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Composite Products plugin <= 8.7.5 versions.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Woocommerce Composite Products | <=8.7.5 |
Update to 8.7.6 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-32801 is high (6.1).
The vulnerability in WooCommerce Composite Products plugin is an Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.
WooCommerce Composite Products plugin versions up to and including 8.7.5 are affected by CVE-2023-32801.
To fix CVE-2023-32801, you should update WooCommerce Composite Products plugin to version 8.7.6 or above.
The Common Weakness Enumeration (CWE) for CVE-2023-32801 is CWE-79 (Cross-Site Scripting).