Products with title variations did not have the titles sanitized when populated with default values, which could potentially result in a stored XSS vulnerability. Although the fix was ostensibly to help compatibility with newer versions of WordPress, it also addresses a potential security flaw. Fixed in WooCommerce 3.2.5
This vulnerability affects the following application versions:
- WooCommerce 3.2.0
- WooCommerce 3.2.0-rc.2
- WooCommerce 3.2.1
- WooCommerce 3.2.2
- WooCommerce 3.2.3
- WooCommerce 3.2.4