Reflected XSS Vulnerability in Wc Recently viewed products
CVE-2024-52484
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 December 2024
What is CVE-2024-52484?
A reflected cross-site scripting vulnerability exists in the Wc Recently Viewed Products plugin developed by Subhasish Manna, impacting versions up to 1.0.1. This vulnerability allows attackers to inject harmful scripts into web pages viewed by users, possibly leading to unauthorized actions and data leakage. Attackers may exploit this flaw by crafting malicious URLs that target unsuspecting users, resulting in compromised web sessions and potential unauthorized access to sensitive information.
Affected Version(s)
Wc Recently viewed products <= 1.0.1