S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0149 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in WooCommerce Stored Exporter plugin for Wordpress affects v. before 2.7.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0149
6.1
CVSS

The WooCommerce Stored Exporter WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vulnerability in the woo_ce admin page.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WooCommerce – Store Exporter
AFFECTED< 2.7.1SAFE ✓≥ 2.7.1
Updated Aug 22, 2026View on NVD →
Detail

WooCommerce Stored Exporter is a WordPress plugin that allows users to export data from their WooCommerce store. This data can include orders, products, customers, and more. The plugin is designed to simplify the process of exporting important data from WooCommerce, enabling users to create custom data exports for a variety of purposes.

The plugin was recently found to be affected by a Reflected Cross-Site Scripting (XSS) vulnerability with the code CVE-2022-0149. This vulnerability is a result of improper sanitization of user input on the woo_ce admin page. As a result, an attacker can inject malicious code into the page, which can then execute in a victim's browser when they visit the page.

Exploitation of this vulnerability can lead to serious consequences. For example, an attacker can use the vulnerability to steal sensitive information from victims, such as user login credentials, payment card information, or other personally identifiable information. Additionally, an attacker can use the vulnerability to inject their own code into the page, enabling them to control the page's behavior and potentially steal even more sensitive information.

Overall, it is important for website owners and developers to stay vigilant when it comes to security vulnerabilities in their digital assets. With the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets, enabling them to take proactive measures to protect against potential threats. By staying informed and taking proactive measures to protect against vulnerabilities, website owners can help ensure the security and integrity of their digital assets.

 

REFERENCES

Solution Advice

Fortunately, there are several precautions that can be taken to protect against this vulnerability. These include:

  • Updating to the latest version of the WooCommerce Stored Exporter plugin, which addresses the vulnerability and includes proper sanitization of user input.
  • Monitoring for any suspicious activity on the woo_ce admin page.
  • Using a web application firewall to filter out malicious code and prevent XSS attacks.
  • Implementing strict input validation and sanitization practices to ensure that all user input is properly filtered and sanitized before being processed by the system.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-0149 scanner - Cross-Site Scripting (XSS) vulnerability in WooCommerce Stored Exporter plugin for Wordpress | S4E