WPC Smart Wishlist for WooCommerce, CVE-2022-0397
- CVE, Research URL
- Home page URL
- Application
- Published on
- Mar 28, 2022
- Research Description
- The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cross-Site Scripting
- Affected versions
-
max 2.9.4.
- Status
-
vulnerable