Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Berocket Subscribe
Filtered by product Advanced Product Labels For Woocommerce
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-0399 1 Berocket 1 Advanced Product Labels For Woocommerce 2022-03-21 4.3 MEDIUM 6.1 MEDIUM
The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's response, leading to a Reflected Cross-Site Scripting