Cross-Site Scripting Vulnerability – WARNING
-
Hi,
In a few days:
2.0.15
2.0.16
2.0.17but reading this below shows that WooCommerce is vulnerable:
“The plugin suffers from a XSS issue due to a failure to properly sanitize user-supplied input to the ‘hide-wc-extensions-message’ parameter in the ‘admin/woocommerce-admin-settings.php’ script. Attackers can exploit this weakness to execute arbitrary HTML and script code in a user’s browser session.“
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2013-5156.phpPATCH: https://github.com/woothemes/woocommerce/commit/4b581450480d74667b76d6ba50961d79a6d7a0c1
when you release a new version 2.0.18?
Viewing 4 replies - 1 through 4 (of 4 total)
Viewing 4 replies - 1 through 4 (of 4 total)
- The topic ‘Cross-Site Scripting Vulnerability – WARNING’ is closed to new replies.