Vulnerabilities > Computy > Bonus FOR WOO > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-11-20 CVE-2023-5140 Cross-site Scripting vulnerability in Computy Bonus for WOO
The Bonus for Woo WordPress plugin before 5.8.3 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
network
low complexity
computy CWE-79
6.1