CVE-2024-51624

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 28, 2025
CWE ID 79

Summary

CVE-2024-51624 is a Cross-site Scripting (XSS) vulnerability affecting Já-Já Pagamentos for WooCommerce, version 1.3.0 and below. The flaw lies in the application's failure to neutralize user-supplied data during web page generation, leading to Reflected XSS. Attackers can exploit this weakness by injecting malicious scripts into web pages viewed by other users, potentially stealing sensitive information or taking control of victims' browsers.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share