CVE-2022-4329

CVE-2022-4329: Product list Widget for Woocommerce <= 1.0 - Reflected XSS

Vendor Unknown
Product Product list Widget for Woocommerce
Published January 2, 2023
Last update April 10, 2025

CVSS base score

What the vulnerability does

01Description

The Product list Widget for Woocommerce WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high privilege one like admin).

Key dates

02Disclosure timeline

January 2, 2023 CVE published
April 10, 2025 Record updated