CVE-2024-11225: Premium Packages – Sell Digital Products Securely <= 5.9.3 - Reflected Cross-Site Scripting via add_query_arg
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of addqueryarg without appropriate escaping on the URL in all versions up to, and including, 5.9.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11225?
CVE-2024-11225 is classified as a high severity vulnerability due to its potential for reflected cross-site scripting, which can be exploited by unauthenticated attackers.
How do I fix CVE-2024-11225?
To fix CVE-2024-11225, update the Premium Packages – Sell Digital Products Securely plugin to version 5.9.4 or later, where the vulnerability is patched.
What type of vulnerability is CVE-2024-11225?
CVE-2024-11225 is a Reflected Cross-Site Scripting (XSS) vulnerability that affects the Premium Packages plugin for WordPress.
Which versions are impacted by CVE-2024-11225?
All versions of the Premium Packages – Sell Digital Products Securely plugin for WordPress up to and including 5.9.3 are impacted by CVE-2024-11225.
Who is affected by CVE-2024-11225?
Website owners using the Premium Packages – Sell Digital Products Securely plugin for WordPress versions up to 5.9.3 are affected by CVE-2024-11225.