Record summary

CVE-2023-28665 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 25, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Woo Bulk Price Update WordPress Plugin

CVE List< 2.2.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWoo Bulk Price Update <2.2.2 - Cross-Site ScriptingCVSS 5.4

The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement.

Remediation

Fixed in version 2.2.2

WeaknessesCWE-79
AuthorsAaban SOlutions, harsh
Template tagscve2023cvewordpresswpwp-pluginwpscanxssauthenticatedwoo-bulk-price-updatetechnocrackersvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:technocrackers:bulk_price_update_for_woocommerce:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2