Reflected XSS Vulnerability in Robokassa Payment Gateway for Woocommerce
CVE-2024-47395
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 October 2024
What is CVE-2024-47395?
A reflected cross-site scripting (XSS) vulnerability exists in the Robokassa payment gateway for WooCommerce, impacting versions from n/a up to 1.6.1. This flaw arises from improper neutralization of input during web page generation, allowing malicious actors to inject arbitrary scripts into web pages viewed by users. This could potentially lead to unauthorized data access, session hijacking, or the delivery of malware. Website administrators using the affected versions of this plugin should take immediate precautions to mitigate risks associated with this vulnerability.
Affected Version(s)
Robokassa payment gateway for Woocommerce <= 1.6.1