CVE-2023-47777: WordPress WooCommerce and WooCommerce Blocks plugins - Auth. Cross-Site Scripting (XSS) vulnerability
Published Nov 30, 2023
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n/a through 8.1.1; WooCommerce Blocks: from n/a through 11.1.1.
Affected Software
2 affected components
Automattic Woocommerce Wordpress<=8.1.1
Automattic Woocommerce Blocks Wordpress<=11.1.1
Remediation
Information
Update WooCommerce to 8.2.0 or a higher version.
Information
Update WooCommerce Blocks to 11.1.2 or a higher version.
Event History
Nov 30, 2023
CVE Published
via MITRE·11:56 AM
Data Sourced
via MITRE·11:56 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-47777.
2
What is the title of the vulnerability?
The title of the vulnerability is WordPress WooCommerce and WooCommerce Blocks plugins - Auth. Cross-Site Scripting (XSS) vulnerability.
3
What is the severity of CVE-2023-47777?
The severity of CVE-2023-47777 is medium.
4
Which software is affected by CVE-2023-47777?
The software affected by CVE-2023-47777 are Automattic WooCommerce (up to version 8.1.1) and Automattic WooCommerce Blocks (up to version 11.1.1).
5
How can the vulnerability CVE-2023-47777 be exploited?
CVE-2023-47777 can be exploited through stored Cross-Site Scripting (XSS) attacks.