Report
The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue
Score:4.7
Severity:Medium
Version: 1.3.7
There is a patch available in v1.3.7.1 and we strongly recommend you update to this version as soon as possible.