First published: Mon Mar 14 2022(Updated: )
The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Reflected Cross-Site Scripting issue
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Woocommerce Persian-woocommerce | <=5.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24940 is a vulnerability in the Persian Woocommerce WordPress plugin through version 5.8.0 that allows for a Reflected Cross-Site Scripting issue.
The severity of CVE-2021-24940 is medium with a CVSS score of 6.1.
CVE-2021-24940 affects the Persian Woocommerce WordPress plugin version 5.8.0 and earlier.
To fix CVE-2021-24940, update the Persian Woocommerce WordPress plugin to version 5.8.1 or later.
Yes, you can find more information about CVE-2021-24940 at the following reference: [https://wpscan.com/vulnerability/1980c5ca-447d-4875-b542-9212cc7ff77f]