Cross-site Scripting Vulnerability in ELEX WooCommerce Dynamic Pricing and Discounts
CVE-2024-31255
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 April 2024
What is CVE-2024-31255?
A Cross-site Scripting (XSS) vulnerability exists within the ELEX WooCommerce Dynamic Pricing and Discounts plugin, allowing attackers to inject malicious scripts through insufficient input validation during web page generation. This flaw affects versions prior to 2.1.2, permitting reflected XSS attacks which can potentially lead to user data exposure. Implementing effective sanitization methods and ensuring software is updated to the latest version are critical steps for maintaining web application security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ELEX WooCommerce Dynamic Pricing and Discounts <= 2.1.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved