CVE · Medium

CVE-2022-4227 — Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 6.0.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-4227 Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 6.0.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 6.0.0 6.0.0 2022-12-05

CVE-2022-4227

The Booster plugins for WordPress contain a security flaw that allows attackers to inject malicious code into web pages. This vulnerability occurs because the plugins do not properly filter and escape user input, making it possible for attackers to trick users into executing arbitrary scripts by clicking on a link. As a result, unauthenticated attackers can potentially inject malicious code, compromising the security of the affected WordPress sites.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.