CVE-2022-1933
17.07.2022, 11:15
The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting
Vendor | Product | Version |
---|---|---|
collect_and_deliver_interface_for_woocommerce_project | collect_and_deliver_interface_for_woocommerce | 𝑥 < 5.1.9 |
𝑥
= Vulnerable software versions