booster_for_woocommerce < 3.8.0 - Cross-Site Scripting in Products Per Page Feature
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-20966. PoCs published by parzel.
AI-analyzed exploit summary This repository contains a README describing CVE-2018-20966, an XSS vulnerability in woocommerce-jetpack versions prior to 3.8.0. No exploit code or detailed technical analysis is provided.
Description
The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.
Exploits (1)
nomisec
WRITEUP
by parzel · poc
https://github.com/parzel/CVE-2018-20966
This repository contains a README describing CVE-2018-20966, an XSS vulnerability in woocommerce-jetpack versions prior to 3.8.0. No exploit code or detailed technical analysis is provided.
Classification
Writeup 80%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target:
woocommerce-jetpack < 3.8.0
No auth needed
Prerequisites:
Access to a vulnerable version of woocommerce-jetpack
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (1)
Core 1
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://wordpress.org/plugins/woocommerce-jetpack/#developers
Scores
CVSS v3
6.1
EPSS
0.0700
EPSS Percentile
91.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Lab Environment
Details
CWE
CWE-79
Status
published
Products (1)
booster/booster_for_woocommerce
< 3.8.0
Published
Aug 12, 2019
Tracked Since
Feb 18, 2026