Skip to content

Latest commit

 

History

History

CVE-2023-25049

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 

CVE-2023-25049

WordPress eCommerce Product Catalog Plugin <= 3.3.4 is vulnerable to Cross Site Scripting (XSS)

Description

This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

Mitigation

Update the WordPress eCommerce Product Catalog plugin to the latest available version (at least 3.3.5).

Timeline

  • 02 February 2023: Reported to Patchstack
  • 02 February 2023: Vulnerability validated
  • 03 February 2023: Vulnerability fixed
  • 06 February 2023: Vulnerability disclosed

References