CVE-2023-2256
Product Addons & Fields for WooCommerce < 32.0.7 - Reflected Cross-Site Scripting
Record summary
CVE-2023-2256 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Product Addons & Fields for WooCommerceDefault status: unaffected | CVE List | Before 32.0.7 | affected |
Nuclei templates
1ProjectDiscoveryHIGHWordPress Product Addons & Fields for WooCommerce < 32.0.7 - Cross-Site ScriptingCVSS 6.1
The Product Addons & Fields for WooCommerce WordPress plugin before version 32.0.7 contains a reflected cross-site scripting vulnerability. The plugin does not properly sanitize and escape some URL parameters in the admin panel, which could allow attackers to execute arbitrary JavaScript code in an administrator's browser context.
Impact
Attackers can inject malicious JavaScript through URL parameters in the admin panel, potentially stealing administrator session cookies and gaining full control over the WooCommerce store and customer data.
Remediation
Update Product Addons & Fields for WooCommerce plugin to version 32.0.7 or later that properly sanitizes and escapes URL parameters in the admin panel.
Source: ProjectDiscovery