YITH WooCommerce Ajax Search Plugin Vulnerable to Stored Cross-Site Scripting
CVE-2024-4455

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
24 May 2024

Summary

The YITH WooCommerce Ajax Search plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate sanitization of user inputs through the 'item' parameter. This vulnerability, present in versions up to and including 2.4.0, allows attackers to inject malicious scripts that execute when users access compromised pages. When exploited, this flaw can lead to unauthorized script execution in the context of the user’s web session, potentially compromising user data and site integrity.

Affected Version(s)

YITH WooCommerce Ajax Search * <= 2.4.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof Zając
.