Unauthenticated Cross-Site Scripting Vulnerability in The Store Exporter for WooCommerce Plugin
CVE-2024-8793

6.1MEDIUM

Summary

The Store Exporter for WooCommerce, an essential plugin for managing product and order exports in WordPress, is vulnerable to Reflected Cross-Site Scripting. This vulnerability arises from the insecure use of the add_query_arg function, which fails to adequately escape the URL parameters. As a consequence, unauthenticated attackers may exploit this flaw to inject malicious scripts into web pages. If an unsuspecting user interacts with a specifically crafted link, the injected scripts could execute in their browser context, posing risks to users and potentially compromising sensitive information. All versions prior to 2.7.2.1 are affected, highlighting the importance for users to update their plugins to mitigate this security risk.

Affected Version(s)

Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More * <= 2.7.2.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dale Mavers
.