Stored XSS Vulnerability in YayCommerce Brand Theme
CVE-2024-54348

6.5MEDIUM

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
16 December 2024

Summary

CVE-2024-54348 is a high-risk vulnerability classified as Cross-site Scripting (XSS) within the YayCommerce Brand theme. This flaw allows attackers to inject malicious scripts into web pages, affecting users who view these pages. Specifically, the vulnerability occurs due to improper neutralization of input during the web page generation process. The affected versions include YayCommerce Brand Theme up to 1.1.6. As a result, users of this theme are urged to update to the latest version immediately to mitigate the risk of potential Stored XSS attacks, where the injected code can be saved and executed in the browsers of users accessing compromised pages.

Affected Version(s)

Brand <= 1.1.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

stealthcopter (Patchstack Alliance)
.