CVE-2024-24885

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 8, 2024
Updated: Aug 2, 2024
CWE ID 79

Summary

CVE-2024-24885 is a Cross-site Scripting (XSS) vulnerability affecting Woocommerce Vietnam Checkout. The issue, which allows Stored XSS, stems from improper neutralization of user input during web page generation. This flaw, present in versions from n/a to 2.0.7, can be exploited to inject malicious scripts into a victim's web browser, potentially leading to unauthorized data access or theft. Attackers can use this vulnerability to execute arbitrary code, manipulate web pages, and steal sensitive user information. Users are advised to update their Woocommerce Vietnam Checkout plugin to a version free from this vulnerability as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share