CVE-2024-13868: Easy Broken Link Checker <= 9.0.2 - Reflected XSS
The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13868?
CVE-2024-13868 has a medium severity rating due to the potential for Reflected Cross-Site Scripting attacks targeting high privilege users.
How do I fix CVE-2024-13868?
To fix CVE-2024-13868, update The URL Shortener WooCommerce WordPress plugin to version 9.0.3 or later, which includes security fixes.
What type of vulnerability is CVE-2024-13868?
CVE-2024-13868 is a Reflected Cross-Site Scripting vulnerability caused by improper sanitization and escaping of output parameters.
Who is affected by CVE-2024-13868?
CVE-2024-13868 affects users of The URL Shortener WooCommerce WordPress plugin versions up to 9.0.2, particularly those with high privilege roles.
Can CVE-2024-13868 lead to account compromise?
Yes, CVE-2024-13868 can lead to account compromise, particularly for high privilege users, if exploited through malicious scripts.