CVE-2023-28665: Technocrackers Bulk Price Update For Woocommerce

Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.

The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user.

Affected products

  • Technocrackers Bulk Price Update For Woocommerce: before 2.2.2 (fixed in 2.2.2)

Published 2023-03-22. Last modified 2026-06-17.