NS WooCommerce Watermark <= 2.11.3 - Abuse of Functionality
2022-03-15 00:00
Felipe Restrepo Rodriguez (pfelilpe)Strategic Overview
StatusPatched in 3.0.0
Affected PluginNS Watermark For WooCommerce
Affected Version
<= 2.11.3CVSS7.5High
CVE
CVE-2022-0989Vulnerability Overview
An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load images that hide malware for example from passing malicious domains to hide their trace, by making them pass through the vulnerable domain.
Technical Analysis
REMEDIATION: Update to version 3.0.0, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C