Reflected Cross-Site Scripting in Compare Products for WooCommerce Plugin
CVE-2024-12435

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
7 January 2025

Summary

The Compare Products for WooCommerce plugin for WordPress is vulnerable to a Reflected Cross-Site Scripting (XSS) flaw through the 's_feature' parameter. This vulnerability arises from inadequate input sanitization and output escaping in all versions up to 3.2.1. By exploiting this weakness, unauthenticated attackers could inject malicious scripts into web pages. These scripts could execute within the user's browser if the attacker successfully persuades them to perform actions such as clicking on a specially crafted link, potentially compromising user data and site integrity.

Affected Version(s)

Compare Products for WooCommerce * <= 3.2.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dale Mavers
.