Reflected XSS Vulnerability in Active Products Tables for WooCommerce
CVE-2024-35730

7.1HIGH

What is CVE-2024-35730?

A reflected Cross-site Scripting (XSS) vulnerability exists in the Active Products Tables for WooCommerce plugin developed by realmag777. This flaw occurs due to improper handling of user input during dynamic web page generation. When exploited, it allows attackers to inject malicious scripts that are executed in the context of the user's browser, potentially compromising user data or redirecting them to harmful sites. Affected versions range from n/a to 1.0.6.3, emphasizing the need for urgent updates to mitigate potential risks.

Affected Version(s)

Active Products Tables for WooCommerce <= 1.0.6.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Le Ngoc Anh (Patchstack Alliance)
.