CVE-2024-12622

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Dec 24, 2024
CWE ID 79

Summary

CVE-2024-12622: The WordPress Simple Shopping Cart plugin contains a Stored Cross-Site Scripting (XSS) vulnerability. This issue affects all versions up to and including 5.0.7. Attackers with contributor-level access and above can exploit this weakness by injecting malicious scripts into the 'wp_cart_button' and 'wp_cart_display_product' shortcodes through insufficient input sanitization and output escaping. These scripts will execute whenever an unsuspecting user accesses a manipulated page.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share