CVE-2023-33216: WordPress WooDiscuz – WooCommerce Comments Plugin <= 2.2.9 is vulnerable to Cross Site Scripting (XSS)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments woodiscuz-woocommerce-comments allows Stored XSS.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.2.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
woodiscuz-woocommerce-commentsto a version that resolves this vulnerability.Fixed in 2.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33216?
The severity of CVE-2023-33216 is medium.
What is the affected software of CVE-2023-33216?
The affected software of CVE-2023-33216 is gVectors Team WooDiscuz - WooCommerce Comments version up to 2.3.0.
What is the vulnerability type of CVE-2023-33216?
The vulnerability type of CVE-2023-33216 is Stored Cross-Site Scripting (XSS).
How can an attacker exploit CVE-2023-33216?
An attacker with admin+ authorization can exploit CVE-2023-33216 by injecting malicious scripts that will execute when a user views the affected page.
Is there a fix available for CVE-2023-33216?
Yes, a fix is available for CVE-2023-33216. It is recommended to update to version 2.2.10 or higher of gVectors Team WooDiscuz - WooCommerce Comments.