PT-2025-9150 · WordPress · Sku Generator For Woocommerce

Dale Mavers

+1

·

Published

2025-03-01

·

Updated

2025-03-01

·

CVE-2024-9212

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SKU Generator for WooCommerce plugin for WordPress versions up to, and including, 1.6.2
Description The issue is related to Reflected Cross-Site Scripting, which occurs due to the use of add query arg without proper escaping on the URL. This allows unauthenticated attackers to inject arbitrary web scripts into pages, which can be executed if a user is tricked into performing a specific action, such as clicking on a link.
Recommendations For versions up to, and including, 1.6.2, update to a version that includes the necessary escaping for the add query arg function to prevent Reflected Cross-Site Scripting attacks.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-9212

Affected Products

Sku Generator For Woocommerce