ZeroHour

CVE-2022-1470

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p54
Published
()
Modified
Description

The Ultimate WooCommerce CSV Importer WordPress plugin through 2.0 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting

Vendors
ultimate woocommerce csv importer project
Products
ultimate woocommerce csv importer
Ecosystems
WordPress, E-commerce
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.