S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0234 Scanner

CVE-2022-0234 scanner - Cross-Site Scripting (XSS) vulnerability in WOOCS plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0234
6.1
CVSS

The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WOOCS – Currency Switcher for WooCommerce. Professional and Free multi currency plugin – Pay in selected currency
AFFECTED< 1.3.7.5SAFE ✓≥ 1.3.7.5
Updated Aug 22, 2026View on NVD →
Detail

The WOOCS plugin for WordPress is a popular tool used to manage multiple currencies on an online store. This plugin facilitates the conversion of prices to the customers' selected currency, providing seamless international transactions. It is specifically designed for online stores and has been widely used by many businesses to cater to their global customers.

Recently, a critical vulnerability in the WOOCS WordPress plugin was detected, named CVE-2022-0234. This vulnerability is due to the fact that the plugin does not properly sanitize and escape user input, specifically the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action. This allows attackers to inject malicious code and execute arbitrary JavaScript on the victim's browser.

Exploiting this vulnerability can lead to a significant security risk for online businesses using the WOOCS plugin. Attackers can exploit this vulnerability to steal customers' sensitive information, such as their usernames, passwords, and credit card details. They can also use this vulnerability for phishing attacks and gain unauthorized access to the website's backend, leading to further attacks and compromise.

s4e.io is a platform that provides comprehensive security testing services for businesses of all sizes. By subscribing to their pro features, businesses can quickly and easily learn about vulnerabilities in their digital assets, including the WOOCS plugin, and take necessary actions to mitigate the risks. By using s4e.io, businesses can ensure the protection of their digital assets from potential threats and attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, businesses using the WOOCS plugin can take the following precautions:

  • Update to the latest version of the plugin (1.3.7.5)
  • Employ security measures such as a Web Application Firewall (WAF) to detect and block any attempted cross-site scripting or other malicious attacks
  • Ensure that the website is running on a secure HTTPS connection
  • Sanitize all user input and escape all special characters before outputting it to the browser
  • Implement a Content Security Policy (CSP) to restrict and control the execution of scripts on the website.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-0234 scanner - Cross-Site Scripting (XSS) vulnerability in WOOCS plugin for WordPress S4E