The Product Addons & Fields for WooCommerce WordPress plugin prior to 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
themeisle product addons \\& fields for woocommerce |