Code Inclusion Vulnerability in Themeisle PPOM for WooCommerce
CVE-2024-35728

5.3MEDIUM

Key Information:

Vendor

Themeisle

Vendor
CVE Published:
10 June 2024

What is CVE-2024-35728?

The Themeisle PPOM for WooCommerce plugin has a vulnerability that allows for code inclusion due to improper neutralization of special elements in output. This issue can be exploited by an attacker to inject malicious content if the affected versions are not remediated. Users should ensure they are using the latest version to mitigate this risk.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.