VYPR

WooCommerce Composite Products

by WordPress

CVEs (2)

  • CVE-2023-32801HigAug 30, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Composite Products plugin <= 8.7.5 versions.

  • CVE-2024-2838MedApr 27, 2024
    risk 0.35cvss 6.4epss 0.00

    The WPC Composite Products for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wooco_components[0][name]' parameter in all versions up to, and including, 7.2.7 due to insufficient input sanitization and output escaping and missing…