Product Feed PRO for WooCommerce, CVE-2022-0426
- CVE, Research URL
- Home page URL
- Application
- Published on
- Mar 07, 2022
- Research Description
- The Product Feed PRO for WooCommerce WordPress plugin before 11.2.3 does not escape the rowCount parameter before outputting it back in an attribute via the woosea_categories_dropdown AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting
- Affected versions
-
max 11.2.3.
- Status
-
vulnerable