CVE-2024-11369
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-11369 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Store credit / Gift cards plugin for WordPress, specifically versions up to and including 1.0.49.46. This issue arises due to insufficient input sanitization and output escaping in the 'coupon', 'start_date', and 'end_date' parameters. Unauthenticated attackers can exploit this vulnerability by injecting arbitrary web scripts, potentially gaining control over users' browser sessions or stealing sensitive information if a user is tricked into performing an action like clicking on a malicious link.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.