CVE-2024-44046

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Oct 6, 2024
Updated: Oct 7, 2024
CWE ID 79

Summary

CVE-2024-44046 is a newly disclosed Cross-Site Scripting (XSS) vulnerability affecting Themify's WooCommerce Product Filter. An attacker can inject malicious code into the application, which is stored and executed in users' browsers when they view affected pages. This issue, present in Themify – WooCommerce Product Filter versions from n/a through 1.5.1, allows an adversary to conduct unauthorized scripting and steal sensitive user data. Users are advised to update their filters to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share