CVE-2024-10563
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Feb 26, 2025
Summary
CVE-2024-10563 is a vulnerability affecting the WooCommerce Cart Count Shortcode plugin before version 1.1.0 for WordPress. This issue permits contributors and above to execute Stored Cross-Site Scripting attacks due to insufficient validation and escaping of shortcode attributes. When the shortcode is embedded in a page or post, malicious scripts can be inserted and executed, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.