Cross-Site Scripting (XSS) Vulnerability in WoodMart
CVE-2023-25790
5.3MEDIUM
What is CVE-2023-25790?
The vulnerability in Xtemos WoodMart theme for WordPress arises from improper authentication and the inadequate neutralization of user input during web page generation. This can result in a Cross-Site Scripting (XSS) attack, where an attacker could execute arbitrary scripts in the context of the user’s browser. Such an attack may allow adversaries to steal sensitive information, hijack user sessions, or redirect users to malicious sites. All versions of WoodMart from n/a up to and including 7.0.4 are impacted, posing significant risks to affected WordPress installations.
Affected Version(s)
WoodMart <= 7.0.4