CVE-2024-10899: WooCommerce Product Table Lite <= 3.8.6 - Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site Scripting
The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.6. This is due to the software allowing users to execute an action that does not properly validate a value before running doshortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The same 'id' parameter is vulnerable to Reflected Cross-Site Scripting as well.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10899?
CVE-2024-10899 has been classified as a high-severity vulnerability due to the potential for arbitrary shortcode execution.
How do I fix CVE-2024-10899?
To mitigate CVE-2024-10899, update the WooCommerce Product Table Lite plugin to version 3.8.7 or later.
What versions of WooCommerce Product Table Lite are affected by CVE-2024-10899?
CVE-2024-10899 affects all versions of WooCommerce Product Table Lite up to and including 3.8.6.
What is the impact of CVE-2024-10899 on my WordPress site?
CVE-2024-10899 allows unauthorized users to execute arbitrary shortcodes, potentially compromising site security and functionality.
Is there a workaround for CVE-2024-10899 if I cannot update immediately?
A potential workaround for CVE-2024-10899 is to restrict user permissions to execute shortcodes until an update can be applied.