Bulk Price Update for Woocommerce <= 2.2.1 - Reflected Cross-Site Scripting
mediumThe Bulk Price Update for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter of the techno_get_products AJAX action in versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attack...
- CVSS:
- 6.1
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.2
- Disclosed:
- Mar 22, 2023