Medium severity6.1OSV Advisory· Published Feb 26, 2019· Updated Jun 17, 2026
CVE-2019-9168
CVE-2019-9168
Description
WooCommerce before 3.5.5 allows XSS via a Photoswipe caption.
Affected products
31.0, 1.0.1, 1.0.2, …+ 1 more
- (no CPE)range: 1.0, 1.0.1, 1.0.2, …
- cpe:2.3:a:woocommerce:woocommerce:*:*:*:*:*:wordpress:*:*range: <3.5.5
Patches
Vulnerability mechanics
References
1- woocommerce.wordpress.com/2019/02/20/woocommerce-3-5-5-security-fix-release/nvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.