CVE-2018-20966

MEDIUM LAB

booster_for_woocommerce < 3.8.0 - Cross-Site Scripting in Products Per Page Feature

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-20966. PoCs published by parzel.

AI-analyzed exploit summary This repository contains a README describing CVE-2018-20966, an XSS vulnerability in woocommerce-jetpack versions prior to 3.8.0. No exploit code or detailed technical analysis is provided.

Description

The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.

Exploits (1)

nomisec WRITEUP
by parzel · poc
https://github.com/parzel/CVE-2018-20966

This repository contains a README describing CVE-2018-20966, an XSS vulnerability in woocommerce-jetpack versions prior to 3.8.0. No exploit code or detailed technical analysis is provided.

Classification
Writeup 80%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: woocommerce-jetpack < 3.8.0
No auth needed
Prerequisites: Access to a vulnerable version of woocommerce-jetpack
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://wordpress.org/plugins/woocommerce-jetpack/#developers

Scores

CVSS v3 6.1
EPSS 0.0700
EPSS Percentile 91.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Lab Environment

COMMUNITY
Community Lab
docker pull wordpress:5.1.1

Details

CWE
CWE-79
Status published
Products (1)
booster/booster_for_woocommerce < 3.8.0
Published Aug 12, 2019
Tracked Since Feb 18, 2026