CVE-2021-24323: Woocommerce < 5.2.0 - Authenticated Stored Cross-Site Scripting (XSS)
Published May 17, 2021
·Updated
When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfilteredhtml is disabled
Affected Software
2 affected componentsFixes available
composer/woocommerce/woocommerce<5.2.0
5.2.0
WooCommerce WooCommerce WordPress<5.2.0
Event History
May 17, 2021
CVE Published
via MITRE·04:48 PM
Data Sourced
via MITRE·04:48 PM
DescriptionWeakness
May 24, 2022
Advisory Published
via GitHub·07:02 PM
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-24323.
2
What is the severity of CVE-2021-24323?
The severity of CVE-2021-24323 is medium.
3
Who can exploit CVE-2021-24323?
High privilege users, such as admin, can exploit CVE-2021-24323.
4
Which version of Woocommerce is affected by CVE-2021-24323?
Woocommerce version up to (exclusive) 5.2.0 is affected by CVE-2021-24323.
5
How can I fix CVE-2021-24323?
To fix CVE-2021-24323, it is recommended to update to a version of Woocommerce higher than 5.2.0.