CVE-2024-10899
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Nov 20, 2024
Updated: Nov 26, 2024
CWE ID 94
Summary
CVE-2024-10899 is a vulnerability affecting the WooCommerce Product Table Lite plugin for WordPress. This issue, present in versions up to 3.8.6, allows unauthenticated attackers to execute arbitrary shortcodes through a flawed action that fails to adequately validate user-supplied values. Consequently, an attacker can exploit this vulnerability to inject malicious code and potentially gain unauthorized access to a WordPress site. Moreover, this same 'id' parameter is susceptible to Reflected Cross-Site Scripting attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share