PT-2023-18559 · WordPress · Addons & Fields For Woocommerce

Alex Sanford

·

Published

2023-05-30

·

Updated

2025-01-10

·

CVE-2023-2256

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Product Addons & Fields for WooCommerce WordPress plugin versions prior to 32.0.7
Description The issue is related to Reflected Cross-Site Scripting due to the plugin's failure to sanitize and escape some URL parameters.
Recommendations For versions prior to 32.0.7, update to version 32.0.7 or later to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-2256

Affected Products

Addons & Fields For Woocommerce