CVE-2024-11331

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Dec 20, 2024
CWE ID 79

Summary

CVE-2024-11331 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the استخراج محصولات ووکامرس (Products and WooCommerce) plugin for WordPress. The issue lies in the improper use of add_query_arg and remove_query_arg functions, which do not provide adequate escaping for URLs. Consequently, unauthenticated attackers can inject malicious scripts into pages by tricking users into clicking on malicious links. This vulnerability poses a significant risk, as it can lead to the execution of arbitrary web scripts and potential unauthorized access or data theft. All versions of the plugin up to and including 2.1.3 are affected.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share