cleantalk
Vulnerabilities and Security Researches

WooCommerce, CVE-2022-2099

CVE, Research URL

CVE-2022-2099

Application

WooCommerce

Published on
Jul 17, 2022
Research Description
The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles
Affected versions
Min 2.0.20, max 5.7.0.
Status
vulnerable