CVE Database /
CVE-2022-4227
CVE · Medium
CVE-2022-4227 — Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 6.0.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-4227
|
Booster for WooCommerce Plus [booster-plus-for-woocommerce] < 6.0.0 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 6.0.0
|
6.0.0 |
2022-12-05 |
—
|
CVE-2022-4227
The Booster plugins for WordPress contain a security flaw that allows attackers to inject malicious code into web pages. This vulnerability occurs because the plugins do not properly filter and escape user input, making it possible for attackers to trick users into executing arbitrary scripts by clicking on a link. As a result, unauthenticated attackers can potentially inject malicious code, compromising the security of the affected WordPress sites.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings