CVE-2021-24974: Product Feed PRO for WooCommerce < 11.0.7 - Subscriber+ Settings Update to Stored XSS
The Product Feed PRO for WooCommerce WordPress plugin before 11.0.7 does not have authorisation and CSRF check in some of its AJAX actions, allowing any authenticated users to call then, which could lead to Stored Cross-Site Scripting issue (which will be triggered in the admin dashboard) due to the lack of escaping.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24974?
CVE-2021-24974 has a medium severity rating due to the risk of stored cross-site scripting vulnerabilities.
How do I fix CVE-2021-24974?
To fix CVE-2021-24974, update the Product Feed PRO for WooCommerce plugin to version 11.0.7 or later.
Who is affected by CVE-2021-24974?
Any WordPress site using Product Feed PRO for WooCommerce plugin version prior to 11.0.7 is affected by CVE-2021-24974.
What type of vulnerability is CVE-2021-24974?
CVE-2021-24974 is classified as a Stored Cross-Site Scripting vulnerability.
What are the potential impacts of CVE-2021-24974?
The potential impacts of CVE-2021-24974 include unauthorized actions by authenticated users leading to exploitation of stored scripts in the admin dashboard.