Blog post

WooCommerce 3.6.4 - CSRF Bypass to Stored XSS

Dennis Brinkrolf photo

Dennis Brinkrolf

Security Researcher

WooCommerce is the most popular e-commerce plugin for WordPress with over 5 million installations. We detected a code vulnerability in the way WooCommerce handles imports of products.