Reflected Cross-Site Scripting in WooCommerce Payments Plugins by WordPress
CVE-2024-11362
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 November 2024
What is CVE-2024-11362?
The Payments and Checkout Plugins for WooCommerce are prone to a reflected cross-site scripting vulnerability due to inadequate escaping of the URL parameters through the use of add_query_arg. This vulnerability affects all versions up to and including 1.112.0, allowing attackers to potentially execute arbitrary web scripts on user sessions. Attackers can exploit this flaw by tricking users into clicking specially crafted links, thereby executing malicious scripts within their browsers.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net * <= 1.112.0
References
CVSS V3.1
Timeline
Vulnerability published