S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-28665 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Woo Bulk Price Update plugin for WordPress affects v. before 2.2.2.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-28665
5.4
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient · user interaction needed.

The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user.

Attack Vector
Network
Privileges Req.
Low
User Interaction
Required
Affected
Woo Bulk Price Update WordPress Pluginby n/a
< 2.2.2
Updated Aug 22, 2026View on NVD →
Detail

The Woo Bulk Price Update WordPress plugin is a tool that allows website administrators to easily update the prices of products in bulk on their online WooCommerce store. With this plugin, users can efficiently update prices for different products from a single page, saving time and effort. It is a popular plugin used by many online retailers who want an efficient way to manage their product prices. 

However, this handy plugin was affected by a serious security vulnerability that could potentially put online stores at risk. CVE-2023-28665 refers to a reflected cross-site scripting (XSS) vulnerability that was found in the plugin. It specifically occurred in the 'page' parameter for the techno_get_products action, and could only be exploited by an authenticated user. 

The vulnerability could allow an attacker to inject malicious code into a web page viewed by other users of the online store. Once a user visits the infected page, the injected code can steal their sensitive information, such as login credentials, credit card details, and personal data. In the wrong hands, this vulnerability could cause significant damage to the reputation and security of an online store. 

In conclusion, the Woo Bulk Price Update WordPress plugin is a useful tool for managing product prices on online stores. However, the CVE-2023-28665 vulnerability found in the plugin poses a serious risk to online businesses. By taking the necessary precautions and relying on trusted security services like s4e.io, website owners can stay protected against cyber threats and ensure that their online stores remain secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, online store owners can take a few precautions. Here are some ways to stay safe:

  • Upgrade to the latest version of the Woo Bulk Price Update plugin, which contains patches to fix the vulnerability
  • Limit user privileges and access to the backend of your online store as much as possible.
  • Use strong and complex passwords for all user accounts.
  • Regularly monitor your online store for any suspicious activity.
  • Consider using a reputable security plugin or service to improve the security of your online store.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.