The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted order forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views order form submissions.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Oct 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Woocommerce
Woocommerce woocommerce |
|
CPEs | cpe:2.3:a:woocommerce:woocommerce:*:*:*:*:free:wordpress:*:* | |
Vendors & Products |
Woocommerce
Woocommerce woocommerce |
Tue, 15 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Woothemes
Woothemes woocommerce |
|
CPEs | cpe:2.3:a:woothemes:woocommerce:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Woothemes
Woothemes woocommerce |
|
Metrics |
ssvc
|
Tue, 15 Oct 2024 05:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted order forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views order form submissions. | |
Title | WooCommerce <= 9.0.2 - Unauthenticated HTML Injection | |
Weaknesses | CWE-79 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-15T05:31:31.921Z
Updated: 2024-10-15T13:53:15.085Z
Reserved: 2024-10-14T17:06:23.598Z
Link: CVE-2024-9944
Vulnrichment
Updated: 2024-10-15T13:53:09.888Z
NVD
Status : Analyzed
Published: 2024-10-15T06:15:02.967
Modified: 2024-10-17T20:47:35.817
Link: CVE-2024-9944
Redhat
No data.