Automattic Woocommerce Blocks vulnerabilities
2 known vulnerabilities affecting automattic/woocommerce_blocks.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2023-47777MEDIUMCVSS 5.4≤ 11.1.1≥ n/a, ≤ 11.1.12023-11-30
CVE-2023-47777 [MEDIUM] CWE-79 CVE-2023-47777: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n/a through 8.1.1; WooCommerce Blocks: from n/a through 11.1.1.
cvelistv5nvd
CVE-2021-32789HIGHCVSS 7.5ExploitedPoC≥ 2.5.0, < 2.5.16≥ 2.6.0, < 2.6.2+29 more2021-07-26
CVE-2021-32789 [HIGH] CWE-89 CVE-2021-32789: woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL in
woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. Via a carefully crafted URL, an exploit can be executed against the `wc/store/products/collection-data?ca
nvd