YITH WooCommerce Ajax Search Plugin Vulnerable to Stored Cross-Site Scripting
CVE-2024-4455
6.1MEDIUM
Summary
The YITH WooCommerce Ajax Search plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate sanitization of user inputs through the 'item' parameter. This vulnerability, present in versions up to and including 2.4.0, allows attackers to inject malicious scripts that execute when users access compromised pages. When exploited, this flaw can lead to unauthorized script execution in the context of the user’s web session, potentially compromising user data and site integrity.
Affected Version(s)
YITH WooCommerce Ajax Search * <= 2.4.0
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Krzysztof Zając