Unprotected Against Reflected Cross-Site Scripting
CVE-2024-9937
6.1MEDIUM
Summary
The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) attacks, primarily due to inadequate input sanitization and output escaping. Attackers can exploit this vulnerability through the 'page' parameter, which permits the injection of arbitrary web scripts into web pages. This can lead to malicious scripts executing in the context of a user's session upon interaction, such as clicking a crafted link. Ensuring proper validation and sanitization of user input is crucial to mitigate this risk and maintain the integrity of WordPress sites.
Affected Version(s)
Woo Manage Fraud Orders * <= 6.1.7
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Colin Xu