Stored Cross-Site Scripting in FiboSearch Plugin for WooCommerce by WordPress
CVE-2023-2450

4.4MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
9 June 2023

Summary

The FiboSearch - AJAX Search for WooCommerce plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability through its admin settings. This flaw arises from inadequate input sanitization and output escaping, enabling authenticated attackers with administrator permissions to inject arbitrary web scripts into pages. These malicious scripts will execute when users access the affected pages. This issue is particularly prevalent in multi-site installations and setups where unfiltered_html is disabled, posing significant risks to site integrity and user security.

Affected Version(s)

FiboSearch – Ajax Search for WooCommerce 1.23.0

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ivan Kuzymchak
.