CVE-2022-0989

CVE-2022-0989: NS WooCommerce Watermark <= 2.11.3 - Abuse of Functionality

Vendor Unknown
Product NS WooCommerce Watermark
Weakness CWE-80 · XSS · basic
Published April 11, 2022
Last update August 2, 2024

CVSS base score

What the vulnerability does

01Description

An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load images that hide malware for example from passing malicious domains to hide their trace, by making them pass through the vulnerable domain.

Key dates

02Disclosure timeline

April 11, 2022 CVE published
August 2, 2024 Record updated