PT-2023-22068 · WordPress · Woocommerce

Myungju Kim

·

Published

2023-06-26

·

Updated

2023-07-05

·

CVE-2023-28991

CVSS v3.1

5.9

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WooCommerce plugin versions prior to 3.0.19
Description A Stored Cross-Site Scripting (XSS) vulnerability exists, allowing authenticated administrators to inject malicious scripts. This issue affects the PI Websolution Order date, Order pickup, Order date time, Pickup Location, and delivery date components.
Recommendations For versions prior to 3.0.19, update to version 3.0.19 or later to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-28991

Affected Products

Woocommerce