CVE-2024-9635

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Nov 23, 2024
CWE ID 79

Summary

CVE-2024-9635 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Checkout with Cash App plugin for WordPress and WooCommerce. Versions up to 6.0.2 are impacted, allowing unauthenticated attackers to inject arbitrary web scripts. This vulnerability arises due to insufficient input sanitization and output escaping in several plugin files. An attacker can exploit this flaw by tricking a user into clicking on a malicious link, leading to the execution of malicious scripts on the victim's browser.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share