CVE-2022-4227

Severity
6.1MEDIUM
EPSS
0.2%
top 57.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 26

Description

The Booster for WooCommerce WordPress plugin before 5.6.3, Booster Plus for WooCommerce WordPress plugin before 6.0.0, Booster Elite for WooCommerce WordPress plugin before 6.0.0 do not escape some URLs and parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages6 packages

🔴Vulnerability Details

2
CVEList
Booster for WooCommerce - Reflected Cross-Site Scripting2022-12-26
GHSA
GHSA-366w-rp6m-qm5x: The Booster for WooCommerce WordPress plugin before 52022-12-26
CVE-2022-4227 (MEDIUM CVSS 6.1) | The Booster for WooCommerce WordPre | cvebase.io