The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| woocommerce/woocommerce(Packagist) | 0 | 6.6.0 | N/A |
CVSS Metrics