QID 996763

Date Published: 2024-01-23

QID 996763: PHP (Composer) Security Update for woocommerce/woocommerce (GHSA-mp46-7x6q-f28m)

When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 4.8 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    Refer to Github security advisory GHSA-mp46-7x6q-f28m for updates and patch information.
    Vendor References

    CVEs related to QID 996763

    Software Advisories
    Advisory ID Software Component Link
    GHSA-mp46-7x6q-f28m woocommerce/woocommerce URL Logo github.com/advisories/GHSA-mp46-7x6q-f28m