First published: Sat Feb 10 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Hosting Pay with Vipps and MobilePay for WooCommerce allows Stored XSS.This issue affects Pay with Vipps and MobilePay for WooCommerce: from n/a through 1.14.13.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wp-hosting Pay With Vipps And Mobilepay For Woocommerce | <=1.14.13 |
Update to 1.14.14 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-51485 has a high severity rating due to its potential to allow stored Cross-site Scripting (XSS) attacks.
To fix CVE-2023-51485, update the Pay with Vipps and MobilePay for WooCommerce plugin to version 1.14.14 or higher.
CVE-2023-51485 affects versions of Pay with Vipps and MobilePay for WooCommerce up to and including 1.14.13.
CVE-2023-51485 is a stored Cross-site Scripting (XSS) vulnerability due to improper input neutralization.
Users of the Pay with Vipps and MobilePay for WooCommerce plugin for WordPress are impacted by CVE-2023-51485.