YITH WooCommerce Ajax Search Plugin Vulnerable to Stored Cross-Site Scripting
CVE-2024-4455
6.1MEDIUM
What is CVE-2024-4455?
The YITH WooCommerce Ajax Search plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate sanitization of user inputs through the 'item' parameter. This vulnerability, present in versions up to and including 2.4.0, allows attackers to inject malicious scripts that execute when users access compromised pages. When exploited, this flaw can lead to unauthorized script execution in the context of the user’s web session, potentially compromising user data and site integrity.
Affected Version(s)
YITH WooCommerce Ajax Search * <= 2.4.0