WooCommerce Customers Manager Plugin Vulnerable to Reflected Cross-Site Scripting
CVE-2024-1743
Currently unrated
What is CVE-2024-1743?
The WooCommerce Customers Manager WordPress plugin before 29.8 does not sanitise and escape various parameters before outputting them back in pages and attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Version(s)
WooCommerce Customers Manager 0 < 29.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.