CVE-2016-10112
Published
CVSS v3
N/A
CVSS v2
3.5
LOW
Affected
1
PROJECT
Description
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.
<p><a href="https://woocommerce.com/woocommerce/" rel="nofollow ugc">WooCommerce</a> is the open-source ecommerce platform for WordPress.</p>
<p>Our core platform is free, flexible, and amplified by a global community. The freedom of open-source means you retain full ownership of your store’s content and data forever.</p>
<p>Whether you’re launching a business, taking brick-and-mortar retail online, or developing sites for clients, use WooCommerce for a store that powerfully blends content and commerce.</p>
<ul>
<li><strong>Create beautiful, enticing storefronts</strong> with <a href="https://woocommerce.com/product-category/themes/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">themes</a> suited to your brand and industry.</li>
<li><strong>Increase revenue</strong> with an optimized <a href="https://woocommerce.com/checkout-blocks/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">shopping cart experience</a> that converts.</li>
<li><strong>Customize product pages in minutes</strong> using modular <a href="https://woocommerce.com/document/woocommerce-blocks/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">product blocks</a>.</li>
<li>Showcase physical and digital goods, product variations, custom configurations, instant downloads, and affiliate items.</li>
<li>Sell <a href="https://woocommerce.com/products/woocommerce-subscriptions/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">subscriptions</a>, <a href="https://woocommerce.com/products/woocommerce-bookings/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">bookings</a>, or <a href="https://woocommerce.com/products/woocommerce-memberships/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">memberships</a>, with our developer-vetted extensions.</li>
<li><strong>Rise to the top of search results</strong> by leveraging <a href="https://www.searchenginejournal.com/wordpress-best-cms-seo/" rel="nofollow ugc">WordPress’ SEO advantage</a>.</li>
<li><strong>Build on a platform that scales.</strong> Get flexible ecommerce for <a href="https://woocommerce.com/high-volume-stores/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">high-volume stores</a>.</li>
</ul>
<h4>ALL THE TOOLS YOU NEED TO SELL</h4>
<p>Built-in tools and popular integrations help you efficiently manage your business operations. Many services are free to add with a single click via the optional <a href="https://woocommerce.com/document/woocommerce-setup-wizard/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">Setup Wizard</a>.</p>
<ul>
<li><strong>Choose how you want to get paid</strong>. Conveniently manage payments from the comfort of your store with <a href="https://woocommerce.com/payments/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">WooPayments</a> (Available in the U.S., U.K., Ireland, Australia, New Zealand, Canada, Spain, France, Germany, and Italy). Securely accept credit cards, mobile wallets, bank transfers, and cash thanks to <a href="https://woocommerce.com/product-category/woocommerce-extensions/payment-gateways/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">100+ payment gateways</a> – including <a href="https://woocommerce.com/products/stripe/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">Stripe</a>, <a href="https://woocommerce.com/products/woocommerce-gateway-paypal-checkout/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">PayPal</a>, and <a href="https://woocommerce.com/products/square/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">Square</a>.</li>
<li><strong>Configure your shipping options</strong>. Print USPS labels right from your dashboard and even schedule a pickup with <a href="https://woocommerce.com/products/shipping/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">WooCommerce Shipping</a> (U.S.-only). Connect with <a href="https://woocommerce.com/product-category/woocommerce-extensions/shipping-methods/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">well-known carriers</a> such as UPS and FedEx – plus a wide variety of delivery, inventory, and fulfillment solutions for your locale.</li>
<li><strong>Simplify sales tax</strong>. Add <a href="https://woocommerce.com/products/tax/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">WooCommerce Tax</a> or <a href="https://woocommerce.com/product-category/woocommerce-extensions/tax?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">similar integrated services</a> to make automated calculations a reality.</li>
</ul>
<h4>Grow your business, add features, and monitor your store on the go</h4>
<p>WooCommerce means business. Keep tabs on the performance metrics most important to you with a powerful and flexible central dashboard built into WooCommerce.</p>
<p>Expand your audience across marketing and social channels with <a href="https://woocommerce.com/products/google-ads/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">Google Ads</a>, <a href="https://woocommerce.com/products/hubspot-for-woocommerce/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">HubSpot</a>, <a href="https://woocommerce.com/products/mailchimp-for-woocommerce/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">Mailchimp</a>, and <a href="https://woocommerce.com/products/facebook/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">Facebook</a> integrations. You can always check out the in-dashboard <a href="https://woocommerce.com/document/marketing-hub/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">Marketing Hub</a> for fresh ideas and tips to help you succeed.</p>
<p>Enhance store functionality with hundreds of free and paid extensions from the <a href="https://woocommerce.com/products/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">WooCommerce Marketplace</a>. Our developers <a href="https://woocommerce.com/document/marketplace-overview/#section-6?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">vet each new extension</a> and regularly review existing extensions to maintain Marketplace quality standards. We are actively <a href="https://woocommerce.com/document/marketplace-overview/#section-2?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">looking for products that help store builders create successful stores</a>.</p>
<p>Manage your store from anywhere with the free WooCommerce <a href="https://woocommerce.com/mobile/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">mobile app</a> (Android and iOS). Spoiler alert: Keep an ear out for the slightly addictive “cha-ching” notification sound each time you make a new sale!</p>
<h4>Own and control your store data – forever</h4>
<p>With <a href="https://woocommerce.com/woocommerce/" rel="nofollow ugc">WooCommerce</a>, your data belongs to you. Always.</p>
<p>If you opt to share <a href="https://woocommerce.com/usage-tracking/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">usage data</a> with us, you can feel confident knowing that it’s anonymized and kept secure. Choose to opt-out at any time without impacting your store.</p>
<p>Unlike hosted ecommerce solutions, WooCommerce store data is future-proof; you’re free to export all your content and take your site to any platform you choose. No restrictions.</p>
<h4>Why developers choose (and love) WooCommerce</h4>
<p>Developers can use <a href="https://woocommerce.com/woocommerce/" rel="nofollow ugc">WooCommerce</a> to create, customize, and scale a store to meet a client’s exact specifications, making enhancements through extensions or custom solutions.</p>
<ul>
<li>Leverage <a href="https://woocommerce.com/document/introduction-to-hooks-actions-and-filters/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">hooks and filters</a> to modify or create functionality.</li>
<li>Integrate virtually any service using a robust <a href="https://developer.woocommerce.com/docs/getting-started-with-the-woocommerce-rest-api/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">REST API</a> and webhooks.</li>
<li>Design and build custom content blocks with React.</li>
<li><a href="https://developer.woocommerce.com/docs/category/extension-development/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">Inspect and modify</a> any aspect of the core plugin code.</li>
<li>Speed up development with a lightning-fast <a href="https://developer.woocommerce.com/docs/category/wc-cli/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">CLI</a>.</li>
</ul>
<p>The core platform is tested rigorously and often, supported by a dedicated development team working across time zones. Comprehensive documentation is updated with each release, empowering you to build exactly the store required.</p>
<h4>Be part of our growing international community</h4>
<p>WooCommerce has a large, passionate community dedicated to helping merchants succeed – and it’s growing fast.</p>
<p>There are <a href="https://woocommerce.com/meetups/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">WooCommerce Meetups</a> in locations around the world that you can attend for free and even get involved in running. These events are a great way to learn from others, share your expertise, and connect with like-minded folks.</p>
<p>WooCommerce also has a regular presence at WordCamps across the globe – we’d love to meet you.</p>
<h4>Contribute and translate</h4>
<p>WooCommerce is developed and supported by Automattic, the creators of WordPress.com and Jetpack. We also have hundreds of independent contributors, and there’s always room for more. Head to the <a href="https://github.com/woocommerce/woocommerce?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">WooCommerce GitHub Repository</a> to find out how you can pitch in.</p>
<p>WooCommerce is translated into multiple languages, including Danish, Ukrainian, and Persian. Help localize WooCommerce even further by adding your locale – visit <a href="https://translate.wordpress.org/projects/wp-plugins/woocommerce/?utm_medium=referral&utm_source=wordpress.org&utm_campaign=wp_org_repo_listing" rel="nofollow ugc">translate.wordpress.org</a>.</p>
<h4>Connection to WooCommerce.com</h4>
<p>You can connect your store to <a href="https://woocommerce.com/" rel="nofollow ugc">WooCommerce.com</a> to manage your subscriptions on WooCommerce Marketplace and receive product updates without leaving WordPress admin. Connection also enables installation of purchased products right from WooCommerce.com and streamlines access to technical support. If you’d like to learn about what data is gathered and how it is used, please refer to our <a href="https://automattic.com/privacy/" rel="nofollow ugc">Privacy Policy</a>.</p>