← Back

CVE-2022-4227

nvd nist
Published: Dec 26, 2022Modified: Apr 14, 2025

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

The Booster for WooCommerce WordPress plugin before 5.6.3, Booster Plus for WooCommerce WordPress plugin before 6.0.0, Booster Elite for WooCommerce WordPress plugin before 6.0.0 do not escape some URLs and parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Affected (3)

3 products
Booster Elite For Woocommerce
Booster For Woocommerce
Booster Plus For Woocommerce
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Before 6.0.0
Before 5.6.3
Before 6.0.0

References (2)

Source: contact@wpscan.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.