cleantalk
Vulnerabilities and Security Researches

WooCommerce, CVE-2021-24323

CVE, Research URL

CVE-2021-24323

Application

WooCommerce

Published on
May 17, 2021
Research Description
When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled
Affected versions
Min -, max 5.2.0.
Status
vulnerable