CVE-2015-2069

WooCommerce
on wordpress-plugin

Published

Severity

CVSS v3:
N/A
CVSS v2:
4.3 MEDIUM

Description

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING in the wc-reports page to wp-admin/admin.php.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:woothemes:woocommerce:*:*:*:*:*:wordpress:*:*n/a2.2.10 (including)*

External Links