CVE-2022-4227
The Booster for WooCommerce WordPress plugin before 5.6.3, Booster Plus for WooCommerce WordPress plugin before 6.0.0, Booster Elite for WooCommerce WordPress plugin before 6.0.0 do not escape some URLs and parameters before outputting them back in…
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
The Booster for WooCommerce WordPress plugin before 5.6.3, Booster Plus for WooCommerce WordPress plugin before 6.0.0, Booster Elite for WooCommerce WordPress plugin before 6.0.0 do not escape some URLs and parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.41% probability · 34th percentile
- CISA KEV
- Not listed
- Affected
- booster/booster elite for woocommerce · booster/booster for woocommerce · booster/booster plus for woocommerce
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/90d3022c-5d35-4ef2-ab87-6919268db890Third Party Advisory
- https://wpscan.com/vulnerability/90d3022c-5d35-4ef2-ab87-6919268db890Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.