{"id":"CVE-2022-2099","aliases":["GHSA-jwvf-28fg-g4xg"],"url":"https://o3.security/vulnerability/CVE-2022-2099","summary":"WooCommerce < 6.6.0 - Admin+ Stored HTML Injection","details":"The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles","published":"2022-07-17T10:35:52Z","modified":"2026-08-12T03:51:14.701971348Z","cvss":{"score":4.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"woocommerce/woocommerce","fixedVersion":"6.6.0"}],"fix":null,"references":[{"type":"WEB","url":"https://wordpress.org/plugins"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/2xxx/CVE-2022-2099.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-2099"},{"type":"EVIDENCE","url":"https://wpscan.com/vulnerability/0316e5f3-3302-40e3-8ff4-be3423a3be7b"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:14.701971348Z"}}