1 results (0.001 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

The WooCommerce Payment Gateway Per Category WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/includes/plugin_settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.10. El plugin WooCommerce Payment Gateway Per Category de WordPress, es vulnerable a un ataque de tipo Cross-Site Scripting Reflejado debido a un valor $_SERVER["PHP_SELF"] reflejado en el archivo ~/includes/plugin_settings.php que permite a atacantes inyectar scripts web arbitrario, en versiones hasta 2.0.10 incluyéndola • https://plugins.trac.wordpress.org/browser/wc-payment-gateway-per-category/tags/2.0.10/includes/plugin_settings.php#L31 https://www.wordfence.com/vulnerability-advisories/#CVE-2021-38341 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •