CVE-2019-14774
The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-admin/admin.php?page=woo-variation-swatches-settings tab parameter.
Source: CVE.org
PLUGIN SECURITY
Beautiful Color, Image and Buttons Variation Swatches For WooCommerce Product Attributes
woo-variation-swatchesvariation swatcheswoocommercewoocommerce attributeswoocommerce variationwoocommerce variation swatches
1 known CVE on file for Woo Variation Swatches. Reported between 2019 and 2019.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2019-14774 | Variation Swatches for WooCommerce [woo-variation-swatches] < 1.0.62 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.0.62 | 1.0.62 | 2019-08-08 | — |
The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-admin/admin.php?page=woo-variation-swatches-settings tab parameter.
Source: CVE.org
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.