WooCommerce Affiliate Plugin - Coupon Affiliates < 4.16.4.5 - Stored Cross-Site Scripting
2022-03-02 00:00
cydaveStrategic Overview
StatusPatched in 4.16.4.5
Affected PluginCoupon Affiliates – Affiliate Plugin for WooCommerce
Affected Version
< 4.16.4.5CVSS7.2High
CVE
CVE-2022-0818Vulnerability Overview
The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated attacker to inject malicious XSS payloads into the settings page of the plugin.
Technical Analysis
REMEDIATION: Update to version 4.16.4.5, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C