WordPress Plugin Vulnerabilities

WooCommerce Subscriptions < 2.6.3 - Unauthenticated Stored Cross-Site Scripting (XSS)

Description

An unauthenticated user could put XSS payload in their billing details when subscribing, which will then be executed in the admin dashboard when moused over.

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
precursorsecurity
Verified
No

Timeline

Publicly Published
2020-07-24 (about 5 years ago)
Added
2020-07-24 (about 5 years ago)
Last Updated
2020-07-25 (about 5 years ago)

Other