Unsecured URL Execution Vulnerability in Booster for WooCommerce Plugin
CVE-2024-9239
6.1MEDIUM
What is CVE-2024-9239?
The Booster for WooCommerce plugin for WordPress contains a reflected cross-site scripting vulnerability due to inadequate output sanitization in the handling of URLs via add_query_arg and remove_query_arg functions. This oversight potentially allows unauthenticated attackers to inject arbitrary scripts into web pages. If a user is deceived into interacting with a malicious link, the injected scripts can be executed in the context of their session, posing risks such as data compromise and unauthorized actions.
Affected Version(s)
Booster for WooCommerce * <= 7.2.3