YITH WooCommerce Ajax Search Plugin Vulnerable to Stored Cross-Site Scripting
CVE-2024-4455
What is CVE-2024-4455?
The YITH WooCommerce Ajax Search plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate sanitization of user inputs through the 'item' parameter. This vulnerability, present in versions up to and including 2.4.0, allows attackers to inject malicious scripts that execute when users access compromised pages. When exploited, this flaw can lead to unauthorized script execution in the context of the user’s web session, potentially compromising user data and site integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
YITH WooCommerce Ajax Search * <= 2.4.0
References
EPSS Score
8% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved