PT-2024-17356 · WordPress · 워드프레스 결제 심플페이 – 우커머스 결제 플러그인

Peter Thaleikis

·

Published

2024-12-07

·

Updated

2024-12-07

·

CVE-2024-11943

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 plugin for WordPress versions up to, and including, 5.2.2
Description The issue is related to Reflected Cross-Site Scripting due to the use of add query arg without appropriate escaping on the URL. This allows unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Recommendations For versions up to, and including, 5.2.2, update to a version that includes the necessary escaping for the add query arg function to prevent Reflected Cross-Site Scripting attacks. As a temporary workaround, consider restricting access to sensitive pages that may be vulnerable to this issue until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-11943

Affected Products

워드프레스 결제 심플페이 – 우커머스 결제 플러그인