CVE · Medium

CVE-2022-2099 — WooCommerce [woocommerce] < 6.6.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2099 WooCommerce [woocommerce] < 6.6.0 Improper Encoding or Escaping of Output Medium 4.8 < 6.6.0 6.6.0 2022-06-20

CVE-2022-2099

The WooCommerce plugin before version 6.6.0 contains a stored HTML injection vulnerability in payment gateway titles caused by inadequate sanitization and escaping of user input. Attackers with high-level authentication privileges, including Store Managers, could exploit this flaw to inject malicious scripts into pages that execute when visitors view the affected content.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.