PT-2024-39495 · WordPress · Extra Product Options Builder For Woocommerce

Aitor F

+1

·

Published

2024-10-24

·

Updated

2024-10-25

·

CVE-2024-9214

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Extra Product Options Builder for WooCommerce plugin for WordPress versions up to, and including, 1.2.133
Description The issue arises from insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts in pages via the RednaoSerializedFields parameter during the creation of a signature file. This enables the execution of injected scripts whenever a user accesses an injected page.
Recommendations For versions up to, and including, 1.2.133, consider disabling the RednaoSerializedFields parameter until a patch is available to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-9214

Affected Products

Extra Product Options Builder For Woocommerce