CVE-2024-11331
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-11331 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the استخراج محصولات ووکامرس (Products and WooCommerce) plugin for WordPress. The issue lies in the improper use of add_query_arg and remove_query_arg functions, which do not provide adequate escaping for URLs. Consequently, unauthenticated attackers can inject malicious scripts into pages by tricking users into clicking on malicious links. This vulnerability poses a significant risk, as it can lead to the execution of arbitrary web scripts and potential unauthorized access or data theft. All versions of the plugin up to and including 2.1.3 are affected.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.