Reflected Cross-Site Scripting in Woo Ukrposhta Plugin for WordPress
CVE-2024-12049
6.1MEDIUM
Summary
The Woo Ukrposhta plugin for WordPress is susceptible to reflected cross-site scripting, allowing unauthenticated attackers to exploit the 'order', 'post', and 'idd' parameters. This vulnerability arises from inadequate input sanitization and output escaping, resulting in the potential injection of arbitrary web scripts. Attackers may trick users into executing malicious scripts by enticing them to click on specially crafted links, thereby compromising the integrity of the affected websites.
Affected Version(s)
Woo Ukrposhta * <= 1.17.11
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dale Mavers