Cardinity Payment Gateway for WooCommerce <= 3.0.6 - Reflected Cross-Site Scripting
mediumThe Cardinity Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amount', 'country', 'currency', 'order_id', 'description', 'return_url', 'project_id', 'signature' parameters in versions up to, and including, 3.0.6 due to insufficient input sanitization and out...
- CVSS:
- 6.1
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.7
- Disclosed:
- Oct 4, 2021