PT-2024-36763 · Woocommerce · Wishlist For Woocommerce: Multi Wishlists Per Customer

·

CVE-2024-56228

·

Published

2024-12-31

·

Updated

2024-12-31

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Wishlist for WooCommerce: Multi Wishlists Per Customer versions prior to 3.1.2
Description The issue is related to improper neutralization of input during web page generation, which allows for Cross-site Scripting (XSS). Specifically, it enables Reflected XSS. This problem affects the Wishlist for WooCommerce: Multi Wishlists Per Customer plugin.
Recommendations For versions prior to 3.1.2, update to a version that contains a fix for this issue to prevent Reflected XSS attacks. As a temporary workaround, consider restricting access to the plugin's functionality until a patch is available. Avoid using the plugin's features that allow user input until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-56228

Affected Products

Wishlist For Woocommerce: Multi Wishlists Per Customer