CVE-2023-37873: WordPress WooCommerce Ship to Multiple Addresses Plugin <= 3.8.5 is vulnerable to Cross Site Scripting (XSS)
Published Aug 5, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Shipping Multiple Addresses plugin <= 3.8.5 versions.
Affected Software
1 affected component
WooCommerce Shipping Multiple Addresses Wordpress<=3.8.5
Remediation
Information
Update to 3.8.6 or a higher version.
Event History
Aug 5, 2023
CVE Published
via MITRE·10:18 PM
Data Sourced
via MITRE·10:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
11:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-37873?
The severity of CVE-2023-37873 is high.
2
How does CVE-2023-37873 affect WooCommerce Shipping Multiple Addresses plugin?
CVE-2023-37873 affects WooCommerce Shipping Multiple Addresses plugin versions <= 3.8.5.
3
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2023-37873?
The Common Weakness Enumeration (CWE) ID associated with CVE-2023-37873 is CWE-79.
4
How can I fix CVE-2023-37873?
To fix CVE-2023-37873, you should update the WooCommerce Shipping Multiple Addresses plugin to a version higher than 3.8.5.
5
Where can I find more information about CVE-2023-37873?
You can find more information about CVE-2023-37873 at this reference: [link](https://patchstack.com/database/vulnerability/woocommerce-shipping-multiple-addresses/wordpress-woocommerce-ship-to-multiple-addresses-plugin-3-8-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve).