Cross-site Scripting (XSS) Vulnerability in YITH WooCommerce Product Add-Ons
CVE-2024-27994
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 March 2024
What is CVE-2024-27994?
A vulnerability exists in YITH WooCommerce Product Add-Ons that allows an attacker to exploit improper neutralization of input during the generation of web pages. This reflected cross-site scripting (XSS) issue can permit the execution of malicious scripts in the context of users, potentially leading to unauthorized access and actions. The issue affects all versions up to 4.5.0, making it crucial for users to assess their installations and apply necessary updates or fixes.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
YITH WooCommerce Product Add-Ons 0 <= 4.5.0