CVE-2024-13472

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Jan 31, 2025
Updated: Feb 11, 2025
CWE ID 94

Summary

CVE-2024-13472 is a critical vulnerability affecting the WooCommerce Product Table Lite plugin for WordPress. The issue allows unauthenticated attackers to execute arbitrary shortcodes due to insufficient input validation. By exploiting this vulnerability, an attacker can inject malicious code, which could lead to data theft or unauthorized access. Additionally, the same 'sc_attrs' parameter is susceptible to Reflected Cross-Site Scripting (XSS), further increasing the potential risks. Versions of the plugin up to 3.9.4 are vulnerable to these attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share