CVE-2023-0948

CVE-2023-0948: Japanized For WooCommerce < 2.5.8 - Reflected XSS

Vendor Unknown
Product Japanized For WooCommerce
Published May 8, 2023
Last update February 4, 2025

CVSS base score

—

What the vulnerability does

01Description

The Japanized For WooCommerce WordPress plugin before 2.5.8 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

Key dates

02Disclosure timeline

May 8, 2023 CVE published
February 4, 2025 Record updated