CVE-2022-0149
WooCommerce – Store Exporter < 2.7.1 - Reflected Cross-Site Scripting (XSS)
Record summary
CVE-2022-0149 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The WooCommerce Stored Exporter WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vulnerability in the woo_ce admin page.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WooCommerce – Store Exporter | CVE List | 2.7.1 to < 2.7.1 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWooCommerce Stored Exporter WordPress Plugin < 2.7.1 - Cross-Site ScriptingCVSS 6.1
The plugin was affected by a reflected cross-site scripting vulnerability in the woo_ce admin page.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of a victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Update to the latest version of the WooCommerce Stored Exporter WordPress Plugin (2.7.1) or apply the vendor-provided patch to mitigate this vulnerability.
Source: ProjectDiscovery