Input validation vulnerability in WooCommerce 4.2.1

The WooCommerce plugin for WordPress is not secure against malicious attacks. A vulnerability known as Reflected Cross-Site Scripting puts it at risk. This vulnerability arises from a lack of sanitization and escaping of SelectWoo, a feature of the plugin. Attackers can use this vulnerability to embed their own scripts into the plugin, which could then be used to access sensitive data or harm the website. Versions of WooCommerce up to 4.2.1 are affected by this vulnerability.

Detected in:

WooCommerce fixed vulnerable versions: >= * < 4.2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.