Reflected XSS in Google Merchant Center Plugin Up to 3.0.11
The XML for Google Merchant Center plugin for WordPress, up to version 3.0.11, has a vulnerability. This is a Reflected Cross-Site Scripting issue via the 'feed_id' parameter. The problem is because of not enough input sanitization and output escaping. Unauthenticated attackers can inject harmful scripts. These scripts run if they can get a user to click on a certain link.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
icopydoc xml for google merchant center |