Stored Cross-Site Scripting Vulnerability in Advanced Woo Search Plugin for WordPress
CVE-2023-2452

4.4MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
9 June 2023

Summary

The Advanced Woo Search plugin for WordPress contains a vulnerability that enables stored cross-site scripting due to inadequate input sanitization and output escaping in its admin settings. This issue allows authenticated attackers with administrator privileges to inject arbitrary scripts that can be executed when users access affected pages. The vulnerability primarily impacts multi-site installations and those with the 'unfiltered_html' feature disabled, highlighting the importance of maintaining strict security protocols and ensuring regular updates.

Affected Version(s)

Advanced Woo Search * <= 2.77

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ivan Kuzymchak
.