WordPress WoodMart Theme <= 7.2.4 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-41872
7.1HIGH
Summary
The Xtemos WoodMart plugin is susceptible to an unauthenticated reflected Cross-Site Scripting (XSS) vulnerability, which affects versions 7.2.4 and earlier. This vulnerability could allow attackers to execute malicious scripts in the context of the user's browser session, potentially compromising sensitive information or executing unintended actions on behalf of the user. It is crucial for users of the WoodMart plugin to update to the latest version to mitigate this risk.
Affected Version(s)
WoodMart <= 7.2.4
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)