Stored Cross-Site Scripting Vulnerability in Advanced Woo Search Plugin for WordPress
CVE-2023-2452
What is CVE-2023-2452?
The Advanced Woo Search plugin for WordPress contains a vulnerability that enables stored cross-site scripting due to inadequate input sanitization and output escaping in its admin settings. This issue allows authenticated attackers with administrator privileges to inject arbitrary scripts that can be executed when users access affected pages. The vulnerability primarily impacts multi-site installations and those with the 'unfiltered_html' feature disabled, highlighting the importance of maintaining strict security protocols and ensuring regular updates.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Advanced Woo Search * <= 2.77
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved