Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "name" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
WordPress Plugin Facebook for WooCommerce Cross-Site Request Forgery (1.9.14)
Jenkins Missing Authorization Vulnerability (CVE-2019-10354)
WordPress Plugin Event Registration 'id' Parameter SQL Injection (5.43)
WebLogic Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2022-22965)