WooCommerce
cpe:2.3:a:woocommerce:woocommerce:*:*:*:*:wordpress:*:*
- <= 9.4.2
A cross-site scripting vulnerability has been identified in the WooCommerce plugin for WordPress, affecting all versions through 9.4.2. The issue arises on the 'customize-store' page, where inadequate input sanitization and output escaping of PostMessage data allow unauthenticated attackers to inject arbitrary scripts. These scripts could execute if a user is tricked into interacting with a link.
Exploitation of this vulnerability allows for cross-site scripting, where injected scripts can be executed in the context of the user's browser.
Users can update to WooCommerce versions 9.3.4 or 9.4.3 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.