Input validation vulnerability in Cost of Goods: Product Cost & Profit Calculator for WooCommerce 3.7.0

The Cost of Goods plugin for WordPress can be easily hacked in versions up to and including 3.7.0. This is because it doesn’t properly clean up the input and output, leaving it open for attackers to add dangerous scripts to pages. This means that anyone with contributor-level access or higher can add their own scripts to pages, which will run whenever someone visits that page.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.