Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-jwvf-28fg-g4xg: WooCommerce WordPress plugin before 6.6.0 vulnerable to stored HTML injection

The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles

ghsa
#git#wordpress

WooCommerce WordPress plugin before 6.6.0 vulnerable to stored HTML injection

Moderate severity GitHub Reviewed Published Jul 18, 2022 • Updated Jul 21, 2022

Related news

CVE-2022-2099

The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles