ZeroHour

CVE-2023-5348

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p43
Published
()
Modified
Description

The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or escape settings values, leading to stored XSS by unauthenticated users.

Vendors
multivendorx
Products
product catalog mode for woocommerce
Ecosystems
WordPress, E-commerce
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.