CVE-2022-2099

MEDIUM4.8EPSS 0.57%

WooCommerce WordPress plugin before 6.6.0 vulnerable to stored HTML injection

Published: 7/18/2022Modified: 2/16/2024
Also known as:GHSA-jwvf-28fg-g4xg

Description

The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.8CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

References (3)