CVE-2023-7151
16.01.2024, 16:15
The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Vendor | Product | Version |
---|---|---|
piwebsolution | product_enquiry_for_woocommerce | 𝑥 < 3.2 |
𝑥
= Vulnerable software versions