2 results (0.004 seconds)

CVSS: 7.1EPSS: 0%CPEs: 1EXPL: 0

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in a3rev Software WooCommerce Predictive Search allows Reflected XSS.This issue affects WooCommerce Predictive Search: from n/a through 6.0.1. Vulnerabilidad de neutralización incorrecta de la entrada durante la generación de páginas web (XSS o 'Cross-site Scripting') en el software a3rev WooCommerce Predictive Search permite XSS reflejado. Este problema afecta a WooCommerce Predictive Search: desde n/a hasta 6.0.1. The WooCommerce Predictive Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. • https://patchstack.com/database/vulnerability/woocommerce-predictive-search/wordpress-predictive-search-for-woocommerce-plugin-6-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

The WooCommerce Predictive Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing nonce check on multiple ajax sync functions in versions up to, and including, 5.8.0. This makes it possible for unauthenticated attackers to sync various product search results such as categories and SKUs, granted they can trick another user into performing an action, such as clicking on a link. • CWE-352: Cross-Site Request Forgery (CSRF) •