First published: Wed Nov 20 2024(Updated: )
The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The same 'id' parameter is vulnerable to Reflected Cross-Site Scripting as well.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WC Product Table Lite | <3.8.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10899 has been classified as a high-severity vulnerability due to the potential for arbitrary shortcode execution.
To mitigate CVE-2024-10899, update the WooCommerce Product Table Lite plugin to version 3.8.7 or later.
CVE-2024-10899 affects all versions of WooCommerce Product Table Lite up to and including 3.8.6.
CVE-2024-10899 allows unauthorized users to execute arbitrary shortcodes, potentially compromising site security and functionality.
A potential workaround for CVE-2024-10899 is to restrict user permissions to execute shortcodes until an update can be applied.