CVE-2022-2099


WooCommerce < 6.6.0 - Admin+ Stored HTML Injection

The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles



We have discovered 474,939 live websites that are affected by CVE-2022-2099.

Contact us to get more info




Affected Software

Product  WooCommerce
Category Ecommerce
Vulnerable Versions
  • from 0 before 6.6
Total Vulnerable Versions582
Vulnerable Domains474,939 live websites (36.75% of WooCommerce install base)


Common Weakness Enumeration


CWE-116 Improper Encoding or Escaping of Output



Details

  • Published - Jul 17, 2022
  • Updated - Jul 4, 2023

Credits

  • Taurus Omar (finder)
  • WPScan (coordinator)





Countries

United States113,367 websites



Italy25,647 websites
Germany25,525 websites
France25,384 websites
GB22,313 websites
Russia22,221 websites
Spain17,003 websites
Vietnam15,198 websites
Netherlands13,275 websites
Poland11,652 websites

TLDs

.com213,642 websites
.ru17,369 websites
.it16,440 websites
.co.uk12,975 websites
.org12,112 websites
.de12,107 websites
.nl10,119 websites
.fr9,270 websites
.net9,043 websites
.com.br8,772 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2022-2099

Top websites that are affected by CVE-2022-2099. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.com United States*,***
***.***********.com Italy*,***
***********.com United States*,***
*****************.com United States*,***
***.*************.com United States*,***
***.com United States*,***
*********.com United States*,***
*******.com United States*,***
***.**********.com United States*,***
*********.com Netherlands**,***
See full domain list