Vulnerability Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Direct checkout, Add to cart redirect, Quick purchase button, Buy now button, Quick View button for WooCommerce plugin <= 2.1.48 versions.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Piwebsolution | Add-To-Cart-Direct-Checkout-For-Woocommerce | <= 2.1.48 |
Related Weaknesses (CWE)
References
- https://patchstack.com/database/vulnerability/add-to-cart-direct-checkout-for-woThird Party Advisory
- https://patchstack.com/database/vulnerability/add-to-cart-direct-checkout-for-woThird Party Advisory
FAQ
What is CVE-2023-28988?
CVE-2023-28988 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Direct checkout, Add to cart redirect, Quick purchase button, Buy now button, Quick View button for WooCommerce plugin ...
How severe is CVE-2023-28988?
CVE-2023-28988 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-28988?
Check the references section above for vendor advisories and patch information. Affected products include: Piwebsolution Add-To-Cart-Direct-Checkout-For-Woocommerce.