CVE-2023-28665
Woo Bulk Price Update <2.2.2 - Cross-Site Scripting
Record summary
CVE-2023-28665 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 25, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Woo Bulk Price Update WordPress Plugin | CVE List | < 2.2.2 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWoo Bulk Price Update <2.2.2 - Cross-Site ScriptingCVSS 5.4
The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement.
Remediation
Fixed in version 2.2.2
Source: ProjectDiscovery