CVE-2024-10563

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 26, 2025

Summary

CVE-2024-10563 is a vulnerability affecting the WooCommerce Cart Count Shortcode plugin before version 1.1.0 for WordPress. This issue permits contributors and above to execute Stored Cross-Site Scripting attacks due to insufficient validation and escaping of shortcode attributes. When the shortcode is embedded in a page or post, malicious scripts can be inserted and executed, posing a significant security risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share