PT-2026-42198 · Pixelyoursite · Cost Of Goods By Pixelyoursite
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cost of Goods by PixelYourSite versions prior to 1.2.13
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS). This occurs via the
csvdata[0][cost of goods value] parameter, enabling the injection of arbitrary web scripts into pages that execute when accessed by a user.Recommendations
Update Cost of Goods by PixelYourSite to version 1.2.13 or later.
Avoid using the
csvdata[0][cost of goods value] parameter until the plugin is updated.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cost Of Goods By Pixelyoursite