Reflected Cross-Site Scripting in Woo Ukrposhta Plugin for WordPress
CVE-2024-12049

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
7 January 2025

Summary

The Woo Ukrposhta plugin for WordPress is susceptible to reflected cross-site scripting, allowing unauthenticated attackers to exploit the 'order', 'post', and 'idd' parameters. This vulnerability arises from inadequate input sanitization and output escaping, resulting in the potential injection of arbitrary web scripts. Attackers may trick users into executing malicious scripts by enticing them to click on specially crafted links, thereby compromising the integrity of the affected websites.

Affected Version(s)

Woo Ukrposhta * <= 1.17.11

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dale Mavers
.