ZeroHour

CVE-2022-2099

PoC
CVSS 3.1
4.8 medium
EPSS
<1%p49
Published
()
Modified
Description

The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles

Vendors
woocommerce
Products
woocommerce
Ecosystems
WordPress, E-commerce
Weakness
CWE-116
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.