Vulnerability Details: Cross-Site Request Forgery (CSRF)/Cross-Site Scripting (XSS) in Advanced Woo Search
One of the changelog entries for the latest version of Advanced Woo Search is “Dev – Update security checks”. That description isn’t entirely accurate as when we looked into what was changed we found that security checks were previously missing and had in fact been added, not updated, in the new version. At least from our quick check over it looks the most serious issue fixed by that change was that there was previously a cross-site request forgery (CSRF)/cross-site scripting (XSS) vulnerability on the plugin’s settings page.
...
This post provides insights on a vulnerability in the WordPress plugin Advanced Woo Search not discovered by us, where the discoverer hadn't provided the details needed for us to confirm the vulnerability while we were adding it to the data set for our service, so the rest of its contents are limited to subscribers of our service.
If you were using our service, you would have already been warned about this vulnerability if your website is vulnerable due to it. You can try out our service for free and then see the rest of the details of the vulnerability.
For existing customers, please log in to your account to view the rest of the contents of the post.