Vulnerability Details CVE-2023-0166
The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.2%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2023-0166
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:-
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.0
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.1
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.10
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.11
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.0
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.1
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.10
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.11
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.12
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.13
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.14
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.15
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.16
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.17
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.18
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.19
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.2
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.20
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.21
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.22
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.23
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.24
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.3
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.4
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.5
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.6
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.7
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.8
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.12.9
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.0
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.1
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.10
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.11
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.12
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.13
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.14
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.15
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.16
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.17
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.18
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.19
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.2
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.20
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.21
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.22
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.23
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.24
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.25
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.26
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.27
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.28
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.29
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.3
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.30
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.31
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.32
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.33
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.34
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.35
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.36
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.37
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.38
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.39
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.4
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.40
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.41
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.5
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.6
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.7
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.8
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.13.9
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.2
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.3
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.4
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.5
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.6
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.7
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.8
-
cpe:2.3:a:pickplugins:product_slider_for_woocommerce:1.9