cleantalk
Vulnerabilities and Security Researches

WPC Smart Wishlist for WooCommerce, CVE-2022-0397

CVE, Research URL

CVE-2022-0397

Published on
Mar 28, 2022
Research Description
The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cross-Site Scripting
Affected versions
max 2.9.4.
Status
vulnerable