Persistent Cross-Site Scripting in WOOF Products Filter for WooCommerce by WordPress
CVE-2020-37174
What is CVE-2020-37174?
The WOOF Products Filter for WooCommerce version 1.2.3 is vulnerable to a persistent cross-site scripting (XSS) flaw. This security issue allows authenticated users to insert malicious scripts into specific text fields, such as 'Text for block toggle' and 'Custom front css styles'. Once saved, these scripts can execute on the frontend, posing risks to all visitors of the site. Without appropriate mitigations, this vulnerability enables attackers to compromise the integrity of web content and potentially access sensitive user data.
Affected Version(s)
Products Filter Professional for WooCommerce 1.2.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
