CVE-2022-2090
17.07.2022, 11:15
The Discount Rules for WooCommerce WordPress plugin before 2.4.2 does not escape a parameter before outputting it back in an attribute of the plugin's discount rule page, leading to Reflected Cross-Site Scripting
Vendor | Product | Version |
---|---|---|
flycart | discount_rules_for_woocommerce | 𝑥 < 2.4.2 |
𝑥
= Vulnerable software versions