vendor:
WooCommerce Products Filter
by:
Shahab.ra.9
8.8
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: WooCommerce Products Filter
Affected Version From: 1.2.3
Affected Version To: 1.2.3
Patch Exists: Yes
Related CWE: N/A
CPE: a:products-filter:woocommerce_products_filter:1.2.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2020
WordPress Plugin WOOF Products Filter for WooCommerce 1.2.3 – Persistent Cross-Site Scripting
A vulnerability in the Wordpress Plugin WOOF Products Filter for WooCommerce 1.2.3 allows an attacker to inject malicious JavaScript code into the application. This code can be executed when a user visits the affected page. The attacker can use this vulnerability to steal user data, hijack user sessions, and perform other malicious activities.
Mitigation:
To mitigate this vulnerability, users should ensure that all plugins are up to date and that any vulnerable plugins are removed from the system.