WordPress Product Specifications for Woocommerce Plugin <= 0.6.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2022-46858
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 May 2023
What is CVE-2022-46858?
A reflected cross-site scripting (XSS) vulnerability exists in the Product Specifications for Woocommerce plugin by Amin A.Rezapour, affecting versions up to 0.6.0. This flaw allows attackers to inject malicious scripts into web pages viewed by users, potentially taking control of user sessions or defacing websites. Affected users are strongly advised to update to the latest version to mitigate this security risk.
Affected Version(s)
Product Specifications for Woocommerce <= 0.6.0