Vulnerabilities > Multivendorx > Product Catalog Mode FOR Woocommerce

DATE CVE VULNERABILITY TITLE RISK
2023-12-18 CVE-2023-5348 Cross-site Scripting vulnerability in Multivendorx Product Catalog Mode for Woocommerce
The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or escape settings values, leading to stored XSS by unauthenticated users.
network
low complexity
multivendorx CWE-79
6.1