Cross-site Scripting (XSS) Vulnerability in YITH WooCommerce Product Add-Ons
CVE-2024-27994
7.1HIGH
Key Information:
- Vendor
- Yith
- Status
- Yith WooCommerce Product Add-ons
- Vendor
- CVE Published:
- 21 March 2024
Summary
A vulnerability exists in YITH WooCommerce Product Add-Ons that allows an attacker to exploit improper neutralization of input during the generation of web pages. This reflected cross-site scripting (XSS) issue can permit the execution of malicious scripts in the context of users, potentially leading to unauthorized access and actions. The issue affects all versions up to 4.5.0, making it crucial for users to assess their installations and apply necessary updates or fixes.
Affected Version(s)
YITH WooCommerce Product Add-Ons <= 4.5.0
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Yudistira Arya (Patchstack Alliance)