PT-2024-30929 · Woocommerce · Eu/Uk Vat Manager For Woocommerce

Abdi Pranata

·

Published

2024-10-20

·

Updated

2024-10-25

·

CVE-2024-44061

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions EU/UK VAT Manager for WooCommerce versions prior to 2.12.14
Description The issue is related to improper neutralization of script-related HTML tags in a web page, which allows Cross-Site Scripting (XSS). This problem enables attackers to use malicious scripts on a website.
Recommendations For versions prior to 2.12.14, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to sensitive areas of the website to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-44061

Affected Products

Eu/Uk Vat Manager For Woocommerce