An update released this week by the developers of WooCommerce, the popular ecommerce plugin for WordPress, patches a flaw that could allow attackers to hijack vulnerable websites.
Han Sahin, co-founder of Dutch security firm Securify, discovered that WooCommerce is plagued by a persistent cross-site scripting (XSS) vulnerability.


