CVE-2024-11362: Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net <= 1.112.0 - Reflected Cross-Site Scripting
The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of addqueryarg without appropriate escaping on the URL in all versions up to, and including, 1.112.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11362?
CVE-2024-11362 has a medium severity due to its potential for Reflected Cross-Site Scripting, which could lead to unauthorized script execution.
How do I fix CVE-2024-11362?
To fix CVE-2024-11362, update the WooCommerce Payments Plugin and Checkout Plugin to a version higher than 1.112.0.
What versions are affected by CVE-2024-11362?
CVE-2024-11362 affects all versions of the WooCommerce Payments Plugin and Checkout Plugin up to and including version 1.112.0.
What is Reflected Cross-Site Scripting as related to CVE-2024-11362?
Reflected Cross-Site Scripting in CVE-2024-11362 allows attackers to inject malicious scripts into web pages, affecting users of the impacted plugins.
What plugins are impacted by CVE-2024-11362?
CVE-2024-11362 impacts the Payments Plugin and Checkout Plugin for WooCommerce.