AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-10112

MEDIUM · CVSS 4.8 EPSS 0.90%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-01-04 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2016-10112
Severity
MEDIUM
CVSS
4.8
EPSS
0.90%
WordPress

Original NVD Description

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.