CVE-2023-0948

CVE-2023-0948: Japanized For WooCommerce < 2.5.8 - Reflected XSS

Vendor Unknown
Product Japanized For WooCommerce
Published May 8, 2023
Last update February 4, 2025

CVSS base score

What the vulnerability does

01Description

The Japanized For WooCommerce WordPress plugin before 2.5.8 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

Key dates

02Disclosure timeline

May 8, 2023 CVE published
February 4, 2025 Record updated