The Bonus for Woo WordPress plugin before 5.8.3 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
References
Link Resource
https://wpscan.com/vulnerability/ee1824e8-09a6-4763-b65e-03701dc3e171 Exploit Product Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2023-11-20T18:55:02.911Z

Updated: 2023-11-20T18:55:02.911Z

Reserved: 2023-09-23T11:50:03.352Z


Link: CVE-2023-5140

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-20T19:15:09.677

Modified: 2023-11-24T18:49:51.220


Link: CVE-2023-5140

JSON object: View

cve-icon Redhat Information

No data.

CWE