Record summary

CVE-2023-2256 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 10, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Product Addons & Fields for WooCommerce

Default status: unaffected

CVE ListBefore 32.0.7affected

Nuclei templates

1
ProjectDiscoveryHIGHWordPress Product Addons & Fields for WooCommerce < 32.0.7 - Cross-Site ScriptingCVSS 6.1

The Product Addons & Fields for WooCommerce WordPress plugin before version 32.0.7 contains a reflected cross-site scripting vulnerability. The plugin does not properly sanitize and escape some URL parameters in the admin panel, which could allow attackers to execute arbitrary JavaScript code in an administrator's browser context.

Impact

Attackers can inject malicious JavaScript through URL parameters in the admin panel, potentially stealing administrator session cookies and gaining full control over the WooCommerce store and customer data.

Remediation

Update Product Addons & Fields for WooCommerce plugin to version 32.0.7 or later that properly sanitizes and escapes URL parameters in the admin panel.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2023wpwordpresswp-pluginxsswoocommercewoocommerce-product-addonauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:themeisle:product_addons_\&_fields_for_woocommerce:*:*:*:*:*:wordpress:*:*
FOFA: body="wp-content/plugins/woocommerce-product-addon/"

Source: ProjectDiscovery

References

2