CVE-2023-49828: WordPress WooCommerce Payments Plugin <= 6.4.2 is vulnerable to Cross Site Scripting (XSS)
Published Dec 14, 2023
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo allows Stored XSS.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.4.2.
Affected Software
1 affected component
Automattic Woopayments Wordpress<6.5.0
Remediation
Information
Update to 6.5.0 or a higher version.
Event History
Dec 14, 2023
CVE Published
via MITRE·02:29 PM
Data Sourced
via MITRE·02:29 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49828?
CVE-2023-49828 has been classified as a high severity vulnerability.
2
How do I fix CVE-2023-49828?
To fix CVE-2023-49828, update the WooPayments plugin to version 6.5.0 or later.
3
What type of vulnerability is CVE-2023-49828?
CVE-2023-49828 is a Stored Cross-site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2023-49828?
Users running versions of the WooPayments plugin prior to 6.5.0 are affected by CVE-2023-49828.
5
What can an attacker do with CVE-2023-49828?
An attacker could exploit CVE-2023-49828 to execute arbitrary JavaScript in the context of the affected user's browser.