Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-0234

25
FAUCET Score

CVE-2022-0234 describes a Reflected Cross-Site Scripting (XSS) vulnerability in the WOOCS WordPress plugin prior to version 1.3.7.5. This flaw stems from insufficient sanitization of the woocs_in_order_currency parameter within the woocs_get_products_price_html AJAX action, allowing unauthenticated attackers to inject malicious scripts. Rated with a CVSS score of 6.1 (Medium), the vulnerability has a network attack vector and low attack complexity, requiring user interaction. Successful exploitation could lead to client-side attacks, including information disclosure and limited integrity impact. While there is no evidence of active exploitation or KEV listing, Nuclei templates exist for detecting this vulnerability. Community discussion and media coverage are minimal, indicating low public attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.3.7.5CPE matchmatch criteria
cpe:2.3:a:pluginus:woocs:*:*:*:*:*:wordpress:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.75%
Probability of exploitation in next 30 days
EPSS Percentile
75.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2022-0234 · Jan 10, 2023
This CVE's current EPSS score of 0.0175 is in the 87th percentile among its peer group of 26,221 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

plugins.trac.wordpress.org / changeset/2659191
Release NotesThird Party Advisory
wpscan.com / vulnerability/fd568a1f-bd51-41bb-960d-f8573b84527b
ExploitThird Party Advisory