CVE-2022-4227EPSS p32.2%
CVE-2022-4227CVE-2022-4227
booster / booster_elite_for_woocommerce
Description
The Booster for WooCommerce WordPress plugin before 5.6.3, Booster Plus for WooCommerce WordPress plugin before 6.0.0, Booster Elite for WooCommerce WordPress plugin before 6.0.0 do not escape some URLs and parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting
Scoring
| CVSS | 6.1 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 0.41% probability of exploitation · percentile 32.2% · 2026-06-19T12:03:05Z |
| Last modified | 2026-06-17 |