First published: Mon Nov 20 2023(Updated: )
The Bonus for Woo WordPress plugin before 5.8.3 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Computy Bonus For Woo | <5.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Bonus for Woo plugin vulnerability is CVE-2023-5140.
The title of the Bonus for Woo plugin vulnerability is 'Reflected Cross-Site Scripting'.
The affected software for the Bonus for Woo plugin vulnerability is Computy Bonus For Woo version up to and excluding 5.8.3 on WordPress.
The severity of the Bonus for Woo plugin vulnerability is medium, with a CVSS score of 6.1.
The Bonus for Woo plugin vulnerability can be exploited through Reflected Cross-Site Scripting attacks, which can be used against high privilege users like admin.