Unauthenticated Cross-Site Scripting Vulnerability in The Store Exporter for WooCommerce Plugin
CVE-2024-8793
Key Information:
- Vendor
- Wordpress
- Status
- Vendor
- CVE Published:
- 1 October 2024
Summary
The Store Exporter for WooCommerce, an essential plugin for managing product and order exports in WordPress, is vulnerable to Reflected Cross-Site Scripting. This vulnerability arises from the insecure use of the add_query_arg function, which fails to adequately escape the URL parameters. As a consequence, unauthenticated attackers may exploit this flaw to inject malicious scripts into web pages. If an unsuspecting user interacts with a specifically crafted link, the injected scripts could execute in their browser context, posing risks to users and potentially compromising sensitive information. All versions prior to 2.7.2.1 are affected, highlighting the importance for users to update their plugins to mitigate this security risk.
Affected Version(s)
Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More * <= 2.7.2.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved