PT-2023-30602 · Automattic · Woocommerce Blocks+1

Rafie Muhammad

·

Published

2023-11-30

·

Updated

2023-12-05

·

CVE-2023-47777

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WooCommerce versions through 8.1.1 WooCommerce Blocks versions through 11.1.1
Description The issue affects Automattic WooCommerce and Automattic WooCommerce Blocks, allowing Stored XSS due to improper neutralization of input during web page generation. This is a Cross-site Scripting vulnerability.
Recommendations For WooCommerce versions through 8.1.1, update to a version later than 8.1.1 to resolve the issue. For WooCommerce Blocks versions through 11.1.1, update to a version later than 11.1.1 to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the web application to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-47777

Affected Products

Woocommerce
Woocommerce Blocks