Sender Newsletter, SMS and Email Marketing Automation for WooCommerce vulnerable to Cross-site Scripting
CVE-2024-43126

7.1HIGH

Key Information:

Summary

The vulnerability arises from improper neutralization of user input during the web page generation process, facilitating reflected Cross-site Scripting (XSS) attacks. Attackers can exploit this flaw to inject malicious scripts into web pages rendered by users, potentially leading to session hijacking, data theft, or other unauthorized actions. The affected product, Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce, has multiple versions influenced by this issue, including releases from n/a up to 2.6.14, highlighting the urgency for users to secure their installations.

Affected Version(s)

Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.6.14

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

Credit

Abdi Pranata (Patchstack Alliance)
.