PT-2022-13175 · WordPress · Product Feed Pro For Woocommerce
Krzysztof Zając
·
Published
2022-03-07
·
Updated
2022-03-11
·
CVE-2022-0426
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Product Feed PRO for WooCommerce WordPress plugin versions prior to 11.2.3
Description
The issue concerns a Reflected Cross-Site Scripting problem. It arises because the
rowCount parameter is not properly escaped before being outputted in an attribute via the /wp-admin/admin-ajax.php action woosea categories dropdown, which is accessible to any authenticated user.Recommendations
For versions prior to 11.2.3, update to version 11.2.3 or later to resolve the issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Product Feed Pro For Woocommerce