CVE

CVE-2015-2069 — WooCommerce [woocommerce] < 2.2.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2015-2069 WooCommerce [woocommerce] < 2.2.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 2.2.11 2.2.11 2015-01-29

CVE-2015-2069

The WooCommerce plugin before version 2.2.11 contains a cross-site scripting vulnerability that permits attackers to inject malicious scripts or HTML code through the query string parameter when accessing the wc-reports page in the WordPress admin panel. This flaw could allow remote attackers to execute arbitrary code in the browsers of site administrators or users with access to that page.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.