Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-1469


The WP Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pec_coupon[code]’ parameter in versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: This can potentially be exploited by lower-privileged users if the `Admin Dashboard Access Permission` setting it set for those users to access the dashboard.


Published

2023-03-17T13:15:10.570

Last Modified

2024-11-21T07:39:15.237

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.4 (MEDIUM)

Weaknesses

-


Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tipsandtricks-hq wp_express_checkout < 2.2.9 Yes

References