Reflected Cross-Site Scripting in Compare Products for WooCommerce Plugin
CVE-2024-12435
6.1MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 7 January 2025
What is CVE-2024-12435?
The Compare Products for WooCommerce plugin for WordPress is vulnerable to a Reflected Cross-Site Scripting (XSS) flaw through the 's_feature' parameter. This vulnerability arises from inadequate input sanitization and output escaping in all versions up to 3.2.1. By exploiting this weakness, unauthenticated attackers could inject malicious scripts into web pages. These scripts could execute within the user's browser if the attacker successfully persuades them to perform actions such as clicking on a specially crafted link, potentially compromising user data and site integrity.
Affected Version(s)
Compare Products for WooCommerce * <= 3.2.1