Cross-site Scripting (XSS) Vulnerability in YITH WooCommerce Product Add-Ons
CVE-2024-27994

7.1HIGH

Key Information:

Vendor
Yith
Status
Yith WooCommerce Product Add-ons
Vendor
CVE Published:
21 March 2024

Summary

A vulnerability exists in YITH WooCommerce Product Add-Ons that allows an attacker to exploit improper neutralization of input during the generation of web pages. This reflected cross-site scripting (XSS) issue can permit the execution of malicious scripts in the context of users, potentially leading to unauthorized access and actions. The issue affects all versions up to 4.5.0, making it crucial for users to assess their installations and apply necessary updates or fixes.

Affected Version(s)

YITH WooCommerce Product Add-Ons <= 4.5.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yudistira Arya (Patchstack Alliance)
.