CVE-2021-24940: Persian Woocommerce <= 5.8.0 - Reflected Cross-Site Scripting
The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Reflected Cross-Site Scripting issue
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24940?
CVE-2021-24940 is a vulnerability in the Persian Woocommerce WordPress plugin through version 5.8.0 that allows for a Reflected Cross-Site Scripting issue.
What is the severity of CVE-2021-24940?
The severity of CVE-2021-24940 is medium with a CVSS score of 6.1.
How does CVE-2021-24940 affect the Persian Woocommerce WordPress plugin?
CVE-2021-24940 affects the Persian Woocommerce WordPress plugin version 5.8.0 and earlier.
How can I fix CVE-2021-24940?
To fix CVE-2021-24940, update the Persian Woocommerce WordPress plugin to version 5.8.1 or later.
Is there a reference for CVE-2021-24940?
Yes, you can find more information about CVE-2021-24940 at the following reference: [https://wpscan.com/vulnerability/1980c5ca-447d-4875-b542-9212cc7ff77f]