We have WooCommerce 9.0.2 installed. It appears to be using Select2 version 4.0.3.. We’ve received notification that Select2 versions < 4.0.8 are susceptible to XXS.
Can this be updated?
Thanks!
Open
Last updated: July 10, 2024
Log in to comment on this feature request.
I am still having same issue, once I updated Select2 manually (by replacing it with updated version) after that, when I updated plugin it replaced with selected version 4.0.3
I am not sure why WooCommerce is using vulnerable version of Select2