core plugin for kitestudio themes <= 2.2.1 - Reflected Cross-Site Scripting
mediumThe core plugin for kitestudio themes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the kite_fetch_woocommerce_shortcode_dom() and kite_fetch_woocommerce_products_loop() functions that are called via nopriv AJAX actions in versions up to, and including 2.2.1. This can be exploited by unauthen...
- CVSS:
- 6.1
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.1
- Disclosed:
- Jun 2, 2022