CVE-2021-24938: WooCommerce Currency Switcher < 1.3.7.1 - Reflected Cross-Site Scripting
Published Dec 6, 2021
·Updated
The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocsupdateprofilesdata AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue
Affected Software
1 affected component
WooCommerce Woocommerce Currency Switcher Wordpress<1.3.7.1
Event History
Dec 6, 2021
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the WOOCS WordPress plugin?
The vulnerability ID for the WOOCS WordPress plugin is CVE-2021-24938.
2
What is the severity of CVE-2021-24938?
The severity of CVE-2021-24938 is medium with a CVSS score of 6.1.
3
What software is affected by CVE-2021-24938?
The WOOCS WordPress plugin before version 1.3.7.1 is affected by CVE-2021-24938.
4
What is the CWE of CVE-2021-24938?
The CWE of CVE-2021-24938 is CWE-79.
5
How do I fix CVE-2021-24938?
To fix CVE-2021-24938, update the WOOCS WordPress plugin to version 1.3.7.1 or later.