Reflected Cross-Site Scripting in Woo Ukrposhta Plugin for WordPress
CVE-2024-12049

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
7 January 2025

Summary

The Woo Ukrposhta plugin for WordPress is susceptible to reflected cross-site scripting, allowing unauthenticated attackers to exploit the 'order', 'post', and 'idd' parameters. This vulnerability arises from inadequate input sanitization and output escaping, resulting in the potential injection of arbitrary web scripts. Attackers may trick users into executing malicious scripts by enticing them to click on specially crafted links, thereby compromising the integrity of the affected websites.

Affected Version(s)

Woo Ukrposhta * <= 1.17.11

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dale Mavers
.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.