VYPR

Japanized For Woocommerce

by Artisanworkshop

CVEs (2)

  • CVE-2023-0948MedMay 8, 2023
    risk 0.40cvss 6.1epss 0.01

    The Japanized For WooCommerce WordPress plugin before 2.5.8 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

  • CVE-2023-0942MedFeb 21, 2023
    risk 0.40cvss 6.1epss 0.01

    The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…