Back

MEDIUM

Product Catalog Enquiry for WooCommerce < 5.0.3 - Unauthenticated Stored XSS via Arbitrary Setting Update

Published Dec 18, 2023

Description

The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or escape settings values, leading to stored XSS by unauthenticated users.

Affected products

Remediation

No remediation recorded yet.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Dec 18, 2023
Updated Aug 2, 2024
Reserved Oct 3, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a