CVE-2023-45006
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2023-45006 is a newly identified vulnerability affecting the WooODT Lite plugin, specifically versions 2.4.6 and below of ByConsole's WooCommerce Order Delivery or Pickup with Date Time Location tool. This issue involves unauthenticated Reflected Cross-Site Scripting (XSS), allowing an attacker to inject malicious code into a user's web browser through a specially crafted link. Successful exploitation could result in stolen sessions, sensitive data exposure, or further compromise of the affected WordPress site. Users are advised to update their plugins to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.