WordPress Plugin Vulnerability Could Expose High Privilege Users to Cross-Site Scripting

CVE-2024-6134
Currently unrated 🤨

Key Information

Vendor
WordPress
Status
WP-cart-for-digital-products
Vendor
CVE Published:
12 August 2024

Summary

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected Version(s)

wp-cart-for-digital-products < 8.5.6

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Bob Matyas
WPScan
.